Description
Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Mesh Configuration Injection
Action: Apply Firmware Update
AI Analysis

Impact

The vulnerability is an incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the cs_broker component, compelling the device to synchronize its mesh configuration with an attacker‑controlled host. This flaw allows an attacker to inject or alter configuration data, potentially taking control over part of the mesh network or disrupting network operation.

Affected Systems

Vendor: TOTOLINK; product: T6 router/access point; firmware version: 4.1.5cu.748_B20211015.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score of <1% suggests low to moderate exploitation probability, though the critical nature of the flaw warrants prompt action. The flaw is exploitable from any network location that can reach the device's MQTT broker. The attack requires only the ability to publish a specially crafted MQTT message; no authentication is needed. Because the flaw allows injection of arbitrary configuration, the potential impact includes unauthorized network re‑configuration, denial of service, and compromise of mesh connectivity. The vulnerability is not listed in the CISA KEV catalog, but the severity and exploitability metrics emphasize the need for remediation.

Generated by OpenCVE AI on September 3, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TOTOLINK T6 firmware update that addresses the access control issue in recv_mesh_info_sync.
  • Restrict MQTT broker access by enforcing firewall rules or ACLs so that only trusted hosts can publish to the cs_broker component.
  • Monitor MQTT traffic and device logs for unexpected configuration pull attempts, alert on anomalous messages.

Generated by OpenCVE AI on September 3, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated MQTT Message Injection for Forced Mesh Configuration Synchronization in TOTOLINK T6

Wed, 02 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated MQTT Message Injection for Forced Mesh Configuration Synchronization in TOTOLINK T6
Weaknesses CWE-284

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Tue, 01 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T17:42:42.990Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51744

cve-icon Vulnrichment

Updated: 2026-09-02T17:42:34.639Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T13:19:45.390

Modified: 2026-09-03T17:21:57.410

Link: CVE-2026-51744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:45:04Z

Weaknesses