SB2026010819 - Exposure of unauthenticated root telnet service in TOTOLINK EX200
Published: January 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper error handling (CVE-ID: CVE-2025-65606)
The vulnerability allows an attacker to compromise the affected system.
The vulnerability exists due to an error in the firmware-upload logic that causes the device to unintentionally start an unauthenticated root-level telnet service in case of unsuccessful firmware update. A remote attacker can trick the victim into uploading malformed firmware files and full control over the device.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.