Executive brief
A security vulnerability has been identified in TOTOLINK EX1200T and N200RE V5 routers that allows an unauthorized person to bypass the login screen. By sending a specially crafted web request, an attacker can gain full administrative access to the device without needing a password. This could lead to the theft of network data, unauthorized changes to internet settings, or a complete takeover of the home or office network.
Technical details
An authentication bypass vulnerability exists in the web management interface of TOTOLINK EX1200T (firmware 4.1.2cu.5215) and N200RE V5 (firmware V9.3.5u.6139_B20201216) routers. The flaw is located in the handling of requests to 'formLoginAuth.htm', where improper authentication logic allows a remote, unauthenticated attacker to bypass the login process. By sending a specifically crafted HTTP request to this endpoint, an attacker can gain full administrative privileges over the device. This is categorized as CWE-287 (Improper Authentication). While the advisory mentions specific firmware versions, users should check for updated firmware from the manufacturer as newer versions (e.g., V9.3.5u.6470 for N200RE) appear to address security concerns.
Affected products
- TOTOLINK EX1200T firmware 4.1.2cu.5215
- TOTOLINK N200RE V5 firmware V9.3.5u.6139_B20201216
Timeline
- 2025-08-13: advisory: Initial NVD publication date