Executive brief
A security vulnerability exists in the TOTOLINK EX200 wireless range extender. The device's file transfer service (FTP) is misconfigured, which could allow an unauthorized person to perform actions they should not be allowed to do. This could potentially lead to unauthorized changes to the device's settings or files, impacting the integrity of the network equipment.
Technical details
A least privilege violation (CWE-272) exists in the TOTOLINK EX200 firmware version 4.0.3c.7646. The vulnerability is rooted in the configuration of the vsftpd service, specifically within the /etc/vsftpd.conf file. A remote, unauthenticated attacker can exploit this misconfiguration to bypass intended privilege restrictions. While the specific function affected is not fully detailed, the flaw allows for unauthorized manipulation of the system's integrity. A public exploit has been released, increasing the risk of active exploitation.
Affected products
- TOTOLINK EX200 4.0.3c.7646
Timeline
- 2026-06-09: advisory: NVD publication date
- 2026-06-09: disclosed: Public disclosure of the vulnerability and exploit