Impact
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an attacker to send a crafted MQTT message to the cs_broker component and restart the cloud update check workflow. The flaw enables unauthenticated control of the update process, which can lead to repeated update attempts or a denial of service but does not expose code execution or device configuration compromise.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other product revisions are listed as vulnerable in the current advisory.
Risk and Exploitability
The vulnerability is remotely exploitable over MQTT, which is often exposed to the internet in consumer networking devices. Likely attack vector involves sending a crafted message to the broker from an external source. The CVSS score of 9.8 indicates a high severity, while the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Publicly known exploits appear limited, but organizations that expose MQTT access should consider the risk moderate to high and mitigate promptly.
OpenCVE Enrichment