Junglewise Threat Intelligence

CVE-2025-51451: TOTOLINK EX1200T and N200RE authentication bypass in formLoginAuth.htm

CVE-2025-51451 · Severity: critical · CVSS 9.8 · Published 2025-08-13

Vendors: TOTOLINK.

Executive brief

A security vulnerability has been identified in TOTOLINK EX1200T and N200RE V5 routers that allows an unauthorized person to bypass the login screen. By sending a specially crafted web request, an attacker can gain full administrative access to the device without needing a password. This could lead to the theft of network data, unauthorized changes to internet settings, or a complete takeover of the home or office network.

Technical details

An authentication bypass vulnerability exists in the web management interface of TOTOLINK EX1200T (firmware 4.1.2cu.5215) and N200RE V5 (firmware V9.3.5u.6139_B20201216) routers. The flaw is located in the handling of requests to 'formLoginAuth.htm', where improper authentication logic allows a remote, unauthenticated attacker to bypass the login process. By sending a specifically crafted HTTP request to this endpoint, an attacker can gain full administrative privileges over the device. This is categorized as CWE-287 (Improper Authentication). While the advisory mentions specific firmware versions, users should check for updated firmware from the manufacturer as newer versions (e.g., V9.3.5u.6470 for N200RE) appear to address security concerns.

Affected products

  • TOTOLINK EX1200T firmware 4.1.2cu.5215
  • TOTOLINK N200RE V5 firmware V9.3.5u.6139_B20201216

Timeline

  • 2025-08-13: advisory: Initial NVD publication date

References