SB2026010819 - Exposure of unauthenticated root telnet service in TOTOLINK EX200



SB2026010819 - Exposure of unauthenticated root telnet service in TOTOLINK EX200

Published: January 8, 2026

Security Bulletin ID SB2026010819
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper error handling (CVE-ID: CVE-2025-65606)

The vulnerability allows an attacker to compromise the affected system.

The vulnerability exists due to an error in the firmware-upload logic that causes the device to unintentionally start an unauthenticated root-level telnet service in case of unsuccessful firmware update. A remote attacker can trick the victim into uploading malformed firmware files and full control over the device. 


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.