CVE-2025-6145

TOTOLINK · EX1200T

A vulnerability has been identified in the TOTOLINK EX1200T range extender that may allow for unauthorized system compromise.

Executive summary

A critical vulnerability found in the TOTOLINK EX1200T range extender poses a severe risk to device and network security.

Vulnerability

This vulnerability is a significant security concern, as it could allow unauthorized users to exploit the device, potentially leading to a full compromise of the range extender's functions.

Business impact

With a CVSS score of 8.8, the potential for impact is high. Unauthorized access to the range extender could facilitate man-in-the-middle attacks or allow an attacker to gain a foothold on the internal network, leading to data exfiltration and significant business disruption.

Remediation

Immediate Action: Update the firmware of all TOTOLINK EX1200T range extenders to the latest vendor-recommended version.

Proactive Monitoring: Review logs for signs of brute-force attempts or unauthorized configuration changes on the range extender.

Compensating Controls: Ensure that the range extender is placed behind a secure gateway and that administrative access is restricted to known-safe IP addresses.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high severity of this vulnerability, immediate remediation is required. Administrators should verify their patching status and ensure all relevant security configurations are hardened to protect against potential exploitation of the EX1200T.