Impact
The vulnerability arises from improper access control in the recvIndirectMeshInfo function of TOTOLINK T6 version 4.1.5cu.748_B20211015. An attacker who can send a crafted MQTT message to the cs_broker component can insert or replace mesh neighbor entries without authentication. This allows the attacker to alter the routing topology of the wireless network, potentially causing loss of connectivity, degrading performance, or enabling further compromises within the mesh. The weakness is an example of improper access control and does not directly lead to code execution or data exfiltration, but it can be leveraged to disrupt network operations or support additional attacks.
Affected Systems
The affected product is TOTOLINK T6 4.1.5cu.748_B20211015. Devices running this firmware build that expose the cs_broker MQTT interface are vulnerable. No vendor‑specified patches are listed in the current advisories, so all installations of this build are impacted until a corrected firmware is released.
Risk and Exploitability
With a CVSS score of 9.8, the flaw is rated critical in terms of potential impact. The EPSS score of less than 1% and the absence from CISA's KEV catalog suggest that exploitation is currently uncommon, but the high severity means that any occurrence could severely disrupt mesh networking by allowing an unauthenticated attacker to manipulate routing topologies. The flaw can be leveraged simply by sending a crafted MQTT message to the cs_broker component, requiring no special privileges, so exposed devices are at significant risk if the vendor has not yet released an updated firmware.
OpenCVE Enrichment