A critical unpatched vulnerability, tracked as CVE-2025-65606, has been disclosed in the TOTOLINK EX200 wireless range extender. The flaw resides in the device's firmware-upload error-handling logic, which, when triggered by a remote authenticated attacker using specially crafted firmware files, causes the device to start an unauthenticated root-level telnet service. This unintended telnet interface grants full system access, allowing attackers to manipulate configurations, execute arbitrary commands, and establish persistent control over the device. The vulnerability requires the attacker to have prior access to the web management interface, but once exploited, it bypasses all authentication for root access.
The TOTOLINK EX200 is no longer actively maintained, and no patches have been released to address this issue. Security experts and CERT/CC recommend that users restrict administrative access to trusted networks, prevent unauthorized access to the management interface, monitor for unusual activity, and consider upgrading to a supported device. The last firmware update for the EX200 was released in February 2023, and the product is now considered end-of-life, increasing the risk for users who continue to operate it without mitigation measures.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On January 6, 2026, CERT/CC published Vulnerability Note VU#295169 warning that CVE-2025-65606 affects the end-of-life TOTOLINK EX200. The advisory said no patch was available and recommended restricting management access, monitoring for telnet activity, and replacing the device.
Researcher Leandro Kogan identified and reported CVE-2025-65606, a flaw in the EX200 firmware-upload logic that can start an unauthenticated root-level telnet service after processing a malformed firmware file. The issue allows a remote authenticated attacker to gain full control of the device.
The TOTOLINK EX200 wireless range extender last received a firmware update in February 2023. Later reporting identified the model as end-of-life and no longer actively maintained.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcesecurityonline.info
Open sourcethecyberexpress.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.