Security researchers have uncovered a critical vulnerability in the TOTOLINK EX200, a widely used Wi-Fi extender, that allows complete remote compromise.
The flaw, tracked as CVE-2025-65606, stems from a severe logic error in how the device processes failed firmware updates.
Because the EX200 has reached End-of-Life (EoL), TOTOLINK has confirmed that no further patches will be released.
This leaves thousands of active devices permanently vulnerable, forcing security experts to recommend immediate hardware replacement.
The “Fail-Open” Nightmare
The vulnerability resides in the device’s web management interface, specifically within the firmware upload mechanism.
By default, the EX200 keeps its Telnet remote administration interface disabled to secure the device against unauthorized command-line access.
However, researchers found that the device fails in an unsafe manner when encountering specific errors. If an authenticated user uploads a specially malformed firmware file, the system’s error-handling logic malfunctions.
Instead of simply rejecting the file and returning to a secure state, the device inadvertently activates the Telnet service.
Crucially, this “panic mode” Telnet instance is launched with root-level privileges and—most alarmingly without a password requirement.
| Feature | Details |
|---|---|
| CVE ID | CVE-2025-65606 |
While the exploit requires an attacker to first authenticate to the web interface, this barrier is often trivial.
Attackers frequently gain initial access via default credentials (which many users fail to change) or through credential stuffing attacks.
Once authenticated, an attacker needs only to upload the malicious file. The device, attempting to handle the “bad” update, triggers the root Telnet service.
The attacker can then simply telnet into the device and execute arbitrary commands with the highest possible privileges.
A compromised extender acts as a powerful beachhead for attackers. With root access, threat actors can:
- Intercept Traffic: Monitor or redirect data flowing through the extender.
- Pivot Attacks: Launch attacks against more secure devices on the local network.
- Establish Persistence: Modify system configurations to maintain access even after reboots.
The CERT Coordination Center (CERT/CC) has acknowledged the issue, crediting researcher Leandro Kogan with the discovery. With no firmware fix forthcoming, the only secure course of action is decommissioning.
Administrators who cannot immediately replace the hardware must ensure the management interface is strictly isolated from the internet and untrusted VLANs.
However, given the hardware’s “zombie” status, physical replacement remains the only guaranteed remediation.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyber Press as a Preferred Source in Google.