logo

CERT/CC warns of critical, unfixed vulnerability in TOTOLINK EX200

ID: d586155d-57b6-5568-a1b5-a5173e7266b8

STIX ID: report--d586155d-57b6-5568-a1b5-a5173e7266b8

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CERT/CC disclosed CVE-2025-65606, an unpatched firmware-upload handler vulnerability in the end-of-life TOTOLINK EX200 range extender that can be triggered by malformed firmware files to start an unauthenticated root telnet service, effectively allowing an authenticated web user to fully compromise the device; TOTOLINK has not patched the flaw, and users are advised to restrict admin access, monitor for telnet activity, and replace affected extenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.