CVE-2025-6145
TOTOLINK · EX1200T
A vulnerability has been identified in the TOTOLINK EX1200T range extender that may allow for unauthorized system compromise.
Executive summary
A critical vulnerability found in the TOTOLINK EX1200T range extender poses a severe risk to device and network security.
Vulnerability
This vulnerability is a significant security concern, as it could allow unauthorized users to exploit the device, potentially leading to a full compromise of the range extender's functions.
Business impact
With a CVSS score of 8.8, the potential for impact is high. Unauthorized access to the range extender could facilitate man-in-the-middle attacks or allow an attacker to gain a foothold on the internal network, leading to data exfiltration and significant business disruption.
Remediation
Immediate Action: Update the firmware of all TOTOLINK EX1200T range extenders to the latest vendor-recommended version.
Proactive Monitoring: Review logs for signs of brute-force attempts or unauthorized configuration changes on the range extender.
Compensating Controls: Ensure that the range extender is placed behind a secure gateway and that administrative access is restricted to known-safe IP addresses.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the high severity of this vulnerability, immediate remediation is required. Administrators should verify their patching status and ensure all relevant security configurations are hardened to protect against potential exploitation of the EX1200T.