Unpatched TOTOLINK EX200 Flaw Enables Root-Level Telnet Access, CERT/CC Warns
ID: 847eac9b-4a80-5820-8a75-71244511f21e
STIX ID: report--847eac9b-4a80-5820-8a75-71244511f21e
Feed Name: The Cyber Express
Threat Score
A critical firmware-upload vulnerability (CVE-2025-65606) in the TOTOLINK EX200 can be triggered by an authenticated user to place the device into an abnormal error state that launches an unauthenticated root telnet service, granting full system access; CERT/CC disclosed the issue on 2026-01-06, no vendor patch is available, and the device is end-of-life, so recommended mitigations are network access restrictions and device replacement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
