CVE-2025-65606: TOTOLINK EX200 Error Opens Root Telnet Door
ID: 9cf6ff28-34f9-525c-9b41-7430b365eab5
STIX ID: report--9cf6ff28-34f9-525c-9b41-7430b365eab5
Feed Name: securityonline.info
A critical firmware-handling flaw (CVE-2025-65606) in the EOL TOTOLINK EX200 Wi‑Fi extender causes the device to enter an abnormal error state when processing certain malformed firmware files, which in turn launches a root-privileged, unauthenticated Telnet service; exploitation requires prior access to the web management interface to upload the malformed firmware. Because the product is no longer maintained and no patch is available, CERT/CC recommends replacing affected devices or isolating them with strict network segmentation and monitoring for unexpected Telnet activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
