Description
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of mesh neighbor records
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from improper access control in the recvIndirectMeshInfo function of TOTOLINK T6 version 4.1.5cu.748_B20211015. An attacker who can send a crafted MQTT message to the cs_broker component can insert or replace mesh neighbor entries without authentication. This allows the attacker to alter the routing topology of the wireless network, potentially causing loss of connectivity, degrading performance, or enabling further compromises within the mesh. The weakness is an example of improper access control and does not directly lead to code execution or data exfiltration, but it can be leveraged to disrupt network operations or support additional attacks.

Affected Systems

The affected product is TOTOLINK T6 4.1.5cu.748_B20211015. Devices running this firmware build that expose the cs_broker MQTT interface are vulnerable. No vendor‑specified patches are listed in the current advisories, so all installations of this build are impacted until a corrected firmware is released.

Risk and Exploitability

With a CVSS score of 9.8, the flaw is rated critical in terms of potential impact. The EPSS score of less than 1% and the absence from CISA's KEV catalog suggest that exploitation is currently uncommon, but the high severity means that any occurrence could severely disrupt mesh networking by allowing an unauthenticated attacker to manipulate routing topologies. The flaw can be leveraged simply by sending a crafted MQTT message to the cs_broker component, requiring no special privileges, so exposed devices are at significant risk if the vendor has not yet released an updated firmware.

Generated by OpenCVE AI on September 3, 2026 at 14:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to a version that removes the access control defect in recvIndirectMeshInfo.
  • If immediate firmware updates are unavailable, restrict incoming MQTT traffic to the cs_broker component to trusted IP ranges or VLANs using firewall or ACL rules.
  • Continuously monitor the mesh neighbor table for unauthorized entries and set alerts for unexpected changes.

Generated by OpenCVE AI on September 3, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Mesh Record Injection via MQTT in TOTOLINK T6

Wed, 02 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Mesh Record Injection via MQTT in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T17:48:28.474Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51765

cve-icon Vulnrichment

Updated: 2026-09-02T17:48:20.401Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T14:17:36.997

Modified: 2026-09-02T18:19:59.340

Link: CVE-2026-51765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:45:04Z

Weaknesses