Impact
The vulnerability lies in the freeStaClient function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where improper access control allows an attacker to send a specially crafted MQTT message to the cs_broker component and force a wireless client to disconnect. The effect is a disruption of the client’s network connectivity, leading to a denial of availability for the affected users without granting any other privileges or malicious code execution.
Affected Systems
The affected product is TOTOLINK’s T6 router running firmware 4.1.5cu.748_B20211015. No other vendors or product variants are currently listed. Users with this specific firmware should identify whether their device matches the version mentioned.
Risk and Exploitability
The CVE has a CVSS score of 9.8, an EPSS score of <1%, and is not listed in CISA’s KEV catalog, indicating a high severity but low probability of exploitation. However, the vulnerability is exploitable remotely via the MQTT service, which is commonly reachable on the device’s internal network or through exposed ports. An unauthenticated attacker can trigger a client disconnect with a single crafted packet, potentially impacting all users connected to the router. The lack of an official fix or workaround means that, until firmware is updated, the risk remains high for any environment where the vulnerable TOTOLINK router is in use.
OpenCVE Enrichment