TOTOLINK EX200 Extender Flaw Allows Attackers Full System Access
A critical security vulnerability has been identified in the TOTOLINK EX200 Wi-Fi extender. This flaw allows attackers to gain complete control over the device due to a logic error in handling failed firmware updates.
A critical security vulnerability has been identified in the TOTOLINK EX200 Wi-Fi extender. This flaw allows attackers to gain complete control over the device due to a logic error in handling failed firmware updates.
The vulnerability, designated as CVE-2025-65606 , involves improper error handling in the firmware-upload mechanism. The Telnet remote administration interface, usually disabled to prevent unauthorized access, is inadvertently activated with root privileges when an authenticated user uploads a malformed firmware file. This service does not require a password.
Full System Compromise: Attackers can modify configurations and execute arbitrary commands. Network Foothold: The compromised device can facilitate attacks on other devices within the local network. Persistent Access: Attackers can establish a permanent presence on the network.
A critical security vulnerability has been identified in the TOTOLINK EX200 Wi-Fi extender.
TOTOLINK has confirmed that no security update will be issued as the EX200 is an End-of-Life (EoL) product. Users are advised to replace it with supported hardware immediately. If replacement is not feasible, administrators should isolate the device, restrict management interface access, and monitor Telnet traffic.
Based on reporting by GBHackers.
