Impact
The meshSlaveUpdate function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access control flaw that permits an unauthenticated attacker to send a crafted MQTT message to the cs_broker component and trigger a firmware download or flash sequence on a slave device. Because the firmware update is initiated without validating the requester, an attacker could supply malicious firmware or otherwise alter the device’s firmware, effectively gaining remote control of the device and enabling arbitrary code execution, configuration changes, or covert persistence.
Affected Systems
TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are confirmed to be vulnerable. No other versions or models are currently listed as affected.
Risk and Exploitability
EPSS score is below 1%, and the CVSS score is 9.8, indicating a critical severity. The vulnerability is not listed in the CISA KEV catalog, but the potential to overwrite firmware implies a high risk of device compromise. The attack vector is inferred to be via an unauthenticated MQTT message to cs_broker; an attacker with network access to the broker can exploit the flaw before any user interaction occurs.
OpenCVE Enrichment