Impact
An incorrect access control check in the meshInfoKick function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to send a crafted MQTT message to the cs_broker component. The message can trigger the system to kick or clean stale mesh information and state, leading to regeneration of mesh metadata. The vulnerability is a classic example of improper access control (CWE‑284).
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other product or vendor versions are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8 and an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is unknown. Based on the description, it is inferred that the attacker does not need to authenticate and can target the MQTT broker if it is accessible. Because any device on the network that can publish to the relevant MQTT topic could trigger the deletion, the attack vector is inferred to be remote via MQTT. The lack of an official patch is inferred from the absence of vendor notification, which raises the risk of denial‑of‑service attacks against the mesh networking functionality.
OpenCVE Enrichment