Description
Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.
Published: 2026-09-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized network reconfiguration
Action: Patch urgently
AI Analysis

Impact

The vulnerability resides in the updateLanIp function of the cs_broker component in TOTOLINK T6 firmware 4.1.5cu.748_B20211015. It permits attackers without authentication to send a specially crafted MQTT message that forces the device to refresh its LAN address state. This can lead to unintended network reconfiguration, potentially disrupting local connectivity or allowing further exploitation of the device. The weakness is a type of improper access control, making the device vulnerable to remote manipulation of its configuration.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product variants are listed.

Risk and Exploitability

Because the flaw can be triggered by unauthenticated actors over an MQTT interface, the potential impact is significant for networks that expose the device to the internet. Publicly available scoring data such as EPSS are not provided, but the CVSS score is 5.3, indicating moderate severity. The absence of authentication controls suggests a high likelihood of exploitation if the MQTT broker is reachable from outside. The vulnerability is not currently catalogued in the CISA KEV database, which may indicate it is not yet widely exploited, but defenders should anticipate possible misuse.

Generated by OpenCVE AI on September 2, 2026 at 01:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest firmware update from TOTOLINK that addresses the updateLanIp function and verifies the fix.
  • If a patch is not yet available, block external MQTT access to the cs_broker component, allowing only local network traffic.
  • Implement network segmentation or firewall rules to isolate the router from untrusted networks, reducing exposure of the MQTT service.
  • Monitor MQTT traffic for abnormal messages directed at cs_broker to detect potential exploitation attempts.

Generated by OpenCVE AI on September 2, 2026 at 01:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in TOTOLINK T6 MQTT LAN IP Refresh Function

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in TOTOLINK T6 MQTT LAN IP Refresh Function
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T15:37:14.697Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51761

cve-icon Vulnrichment

Updated: 2026-09-01T15:36:22.963Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T14:17:36.520

Modified: 2026-09-01T21:00:36.830

Link: CVE-2026-51761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:30:20Z

Weaknesses