Impact
The vulnerability resides in the meshSlaveUpgfw function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. It allows an unauthenticated attacker to craft an MQTT message to the cs_broker component, triggering the device to start flashing firmware using existing upgrade files. Because flashing firmware writes arbitrary code to the device’s storage, this flaw can effectively result in Remote Code Execution, granting full control over the affected router.
Affected Systems
This issue affects TOTOLINK brand routers running firmware version 4.1.5cu.748_B20211015. No other products are listed.
Risk and Exploitability
The CVSS score is 5.9, and EPSS data is not available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be network‑based via MQTT connections to the cs_broker component, and it requires no authentication. Given the lack of public exploitation data, the likelihood remains uncertain, but the potential impact is severe enough to warrant urgent attention.
OpenCVE Enrichment