IoT, Vulnerability Management

Unpatched flaw in TOTOLINK EX200 extender allows remote control

Cybersecurity Alert Critical System Vulnerability Detected

A critical security vulnerability has been identified in the TOTOLINK EX200 wireless range extender, potentially allowing remote attackers to gain complete control over the device. The flaw, tracked as CVE-2025-65606, resides in the firmware-upload error handling, which can inadvertently activate an unauthenticated root-level telnet service, according to a recent report by The Hacker News.

The vulnerability requires an attacker to first authenticate to the device's web management interface to access the firmware upload functionality. By uploading a malformed firmware file, the attacker can trigger an error state that launches a telnet service with root privileges, bypassing authentication. This allows for potential device hijacking, manipulation of configurations, execution of arbitrary commands, and establishment of persistence on the compromised device. The CERT Coordination Center (CERT/CC) reported that TOTOLINK has not released a patch, and the product is reportedly no longer actively maintained, with its last firmware update in February 2023.

Given the lack of a patch for the TOTOLINK EX200, users are strongly advised to implement immediate security measures. These include restricting administrative access to trusted networks, preventing unauthorized access to the management interface, and actively monitoring for any suspicious activity. Furthermore, users should consider upgrading to a newer, supported model to ensure ongoing security updates and protection against emerging threats. This situation highlights the ongoing risks associated with using end-of-life network devices and the importance of proactive device management.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds