CVE-2025-6302

TOTOLINK · EX1200T

A critical vulnerability has been identified in the TOTOLINK EX1200T that may lead to unauthorized system-level access.

Executive summary

The TOTOLINK EX1200T is affected by a critical, high-severity vulnerability that poses an immediate risk of unauthorized access and system-wide compromise.

Vulnerability

This vulnerability, classified as critical, impacts the EX1200T firmware; its high CVSS score of 8.8 highlights the potential for severe security degradation of the device.

Business impact

A successful exploit of this vulnerability could lead to a total loss of control over the EX1200T, potentially allowing an attacker to pivot into the internal network. The 8.8 CVSS score justifies a high-priority response to prevent the possibility of significant reputational or operational damage resulting from unauthorized access.

Remediation

Immediate Action: Apply the latest security firmware update for the EX1200T immediately upon release by the manufacturer.

Proactive Monitoring: Continuously audit access logs for unauthorized administrative activity and monitor for unusual traffic patterns originating from the device.

Compensating Controls: Deploy a Web Application Firewall (WAF) or equivalent network filter to block suspicious traffic patterns targeting the device’s administrative interface.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the critical classification and high CVSS score, this vulnerability warrants immediate remediation. Security teams must ensure that all EX1200T devices are patched promptly and that management access is restricted to prevent unauthorized exploitation.