OSV 1.4.0 · unreviewed · 修改于 2026-09-03 02:32
发布时间
2026-09-02 02:30
GitHub 审查时间
—
NVD 发布时间
2026-09-02 00:17
源文件
advisories/unreviewed/2026/09/GHSA-c6w3-3vcp-m3h3/GHSA-c6w3-3vcp-m3h3.json
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..
该公告没有提供结构化的受影响软件包信息。