Junglewise Threat Intelligence

CVE-2026-11620: TOTOLINK EX200 least privilege violation in vsftpd.conf

CVE-2026-11620 · Severity: medium · CVSS 5.3 · Published 2026-06-09

Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the TOTOLINK EX200 wireless range extender. The device's file transfer service (FTP) is misconfigured, which could allow an unauthorized person to perform actions they should not be allowed to do. This could potentially lead to unauthorized changes to the device's settings or files, impacting the integrity of the network equipment.

Technical details

A least privilege violation (CWE-272) exists in the TOTOLINK EX200 firmware version 4.0.3c.7646. The vulnerability is rooted in the configuration of the vsftpd service, specifically within the /etc/vsftpd.conf file. A remote, unauthenticated attacker can exploit this misconfiguration to bypass intended privilege restrictions. While the specific function affected is not fully detailed, the flaw allows for unauthorized manipulation of the system's integrity. A public exploit has been released, increasing the risk of active exploitation.

Affected products

  • TOTOLINK EX200 4.0.3c.7646

Timeline

  • 2026-06-09: advisory: NVD publication date
  • 2026-06-09: disclosed: Public disclosure of the vulnerability and exploit

References

Related threats