CVE-2025-6144

TOTOLINK · EX1200T

A vulnerability has been identified in the TOTOLINK EX1200T range extender that may allow for unauthorized system compromise.

Executive summary

A high-severity vulnerability in the TOTOLINK EX1200T range extender creates a significant risk of unauthorized device manipulation and network disruption.

Vulnerability

This vulnerability affects the device's security posture, potentially allowing attackers to exploit the software to gain unauthorized control over the extender.

Business impact

Reflecting a CVSS score of 8.8, this flaw presents a substantial risk to network security. Successful exploitation could result in the compromise of wireless communications and unauthorized access to the management interface, potentially leading to service degradation or network-wide data interception.

Remediation

Immediate Action: Apply the vendor-provided firmware update to all affected EX1200T units to mitigate the vulnerability.

Proactive Monitoring: Monitor network traffic for unusual patterns and audit device configuration for unauthorized changes.

Compensating Controls: Use a Web Application Firewall or similar network security tool to monitor and block malicious requests targeting the device’s administrative interface.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The severity of this issue necessitates swift remediation. IT administrators should prioritize updating these devices to ensure they are protected against potential exploitation, as these extenders can be a weak point in network perimeter security.