CyberRota Analysis
AI-GeneratedThe vulnerability in the meshSlaveUpgfw function of TOTOLINK T6 allows unauthenticated attackers to initiate firmware flashing by sending a specially crafted MQTT message to the cs_broker component, potentially leading to unauthorized firmware modifications. This could compromise the integrity and security of the device, making it a critical concern for users and administrators of affected TOTOLINK products. Organizations utilizing these devices should prioritize patching or mitigating this vulnerability to prevent exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.