logo

Unpatched TOTOLINK EX200 Flaw Enables Root-Level Telnet Access, CERT/CC Warns

ID: 847eac9b-4a80-5820-8a75-71244511f21e

STIX ID: report--847eac9b-4a80-5820-8a75-71244511f21e

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical firmware-upload vulnerability (CVE-2025-65606) in the TOTOLINK EX200 can be triggered by an authenticated user to place the device into an abnormal error state that launches an unauthenticated root telnet service, granting full system access; CERT/CC disclosed the issue on 2026-01-06, no vendor patch is available, and the device is end-of-life, so recommended mitigations are network access restrictions and device replacement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.