Impact
The recvClearPairCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains insufficient access controls. Based on the description, an unauthenticated attacker can send a crafted MQTT message to the cs_broker component, causing the device to reset its pairing state and reboot. The CVSS score of 9.8 reflects the critical nature of this flaw, indicating that the attacker can cause loss of connectivity for authorized users and disrupt network services.
Affected Systems
The vulnerability affects TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015. No other vendors or products are listed in the CNA data, so the impact is limited to this specific model and firmware revision.
Risk and Exploitability
The attack requires delivering a specially structured MQTT message to a component reachable from the network where the device operates. Based on the description, the attack vector is via any host that can reach the cs_broker. Because authentication is bypassed, the exploit can be performed from any network host, leading to a high risk. The CVSS score of 9.8 indicates critical severity, and the EPSS score of <1% suggests a low yet nonzero exploitation probability. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment