Impact
The vulnerability is an incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the cs_broker component, compelling the device to synchronize its mesh configuration with an attacker‑controlled host. This flaw allows an attacker to inject or alter configuration data, potentially taking control over part of the mesh network or disrupting network operation.
Affected Systems
Vendor: TOTOLINK; product: T6 router/access point; firmware version: 4.1.5cu.748_B20211015.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score of <1% suggests low to moderate exploitation probability, though the critical nature of the flaw warrants prompt action. The flaw is exploitable from any network location that can reach the device's MQTT broker. The attack requires only the ability to publish a specially crafted MQTT message; no authentication is needed. Because the flaw allows injection of arbitrary configuration, the potential impact includes unauthorized network re‑configuration, denial of service, and compromise of mesh connectivity. The vulnerability is not listed in the CISA KEV catalog, but the severity and exploitability metrics emphasize the need for remediation.
OpenCVE Enrichment