Impact
TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains a flaw in the sendStaticInfoToMaster function where access controls are incorrectly implemented. The result is that an attacker who can send MQTT messages to the cs_broker component can modify stored slave inventory records without authentication. This allows an adversary to alter device configuration or inventory information, potentially impacting device management or network visibility.
Affected Systems
The affected product is TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. The vulnerability resides in the cs_broker MQTT component of the device firmware. No official patch or version upgrade has been released by TOTOLINK for this specific flaw, so affected devices remain at risk until a firmware update is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating moderate severity, and does not have an EPSS score or KEV listing, suggesting no publicly documented exploits yet. However, unauthenticated access to the MQTT interface provides a path for remote or network‑based adversaries to craft a message that modifies slave inventory records. The impact is high because the attacker can alter configuration or inventory data, potentially enabling further attacks or disrupting network management. Mitigation requires either firmware updates, disabling or blocking the MQTT broker, or limiting network exposure of the device to trusted hosts only.
OpenCVE Enrichment