Impact
An access control flaw in the sendToMasterQosConfig function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to send a crafted MQTT message to the cs_broker component and forward attacker‑controlled QoS settings to the master device. The attacker can alter how traffic is prioritized, potentially degrading performance or denying service to legitimate traffic. The flaw does not provide remote code execution but enables configuration tampering that can disrupt network quality of service.
Affected Systems
The vulnerability affects TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015. No other product or version information is provided.
Risk and Exploitability
The exploit does not require authentication, so an attacker who can reach the MQTT broker can abuse the flaw. EPSS score < 1%, but the lack of authentication and the ability to alter configuration implies a moderate to high risk of exploitation. The CVSS score of 9.8 reflects critical severity. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits are documented at this time. Based on the description, it is inferred that the likely attack vector is through the MQTT protocol to the cs_broker component, so network‑level defenses such as access control or isolation apply.
OpenCVE Enrichment