Impact
The setDevReboot function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access control flaw that permits any attacker to trigger a router reboot without credential verification. When an attacker sends a crafted MQTT message to the cs_broker component, a master device will reboot itself, and on a mesh network it will propagate the reboot command to all associated slave nodes. The resulting loss of connectivity can disrupt network services and temporarily deny access to users, with significant availability impact, but does not directly compromise data confidentiality or integrity.
Affected Systems
Affected devices are TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other product or version data is currently reported.
Risk and Exploitability
The vulnerability is exploitable through an unauthenticated MQTT interface, an attack path that requires the attacker to have network access to the router. The CVSS score of 7.5 indicates a high severity. It remains not listed in CISA KEV, and the EPSS score is not published. Operators should evaluate the risk as significant enough to warrant prompt mitigation or patching if an update becomes available.
OpenCVE Enrichment