CVE-2025-51451

9.8

TOTOLINK · EX1200T

A critical authentication bypass vulnerability exists in TOTOLINK EX1200T firmware 4.1.2cu.5215, allowing unauthenticated attackers to bypass login via the formLoginAuth.htm endpoint.

Executive summary

A critical authentication bypass vulnerability in TOTOLINK EX1200T firmware allows unauthenticated attackers to gain full administrative access.

Vulnerability

This is an authentication bypass vulnerability. An unauthenticated attacker can exploit the formLoginAuth.htm function to circumvent security controls and access the device without valid credentials.

Business impact

Successful exploitation grants an attacker full control over the affected network device. Given the CVSS score of 9.8, this vulnerability poses a severe risk, as it enables unauthorized configuration changes, traffic interception, and potential pivot points into the internal network, leading to significant data compromise and operational downtime.

Remediation

Immediate Action: Review the vendor's official support portal for firmware updates; if no patch is available, isolate the device from the public internet.

Proactive Monitoring: Monitor network traffic for unusual requests directed at formLoginAuth.htm and review device access logs for unauthorized administrative sessions.

Compensating Controls: Deploy a Web Application Firewall (WAF) or ingress filtering to block external access to the device's management interface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical severity and the nature of the authentication bypass, organizations using the TOTOLINK EX1200T should prioritize restricting management access to trusted internal networks only. Apply any available firmware updates immediately and transition to a more secure hardware solution if the vendor does not provide a timely fix.

More TOTOLINK CVEs