NVD disclosure day

Published threat advisories for August 13, 2025

CVE advisoryCRITICAL

CVE-2025-51451

TOTOLINK EX1200T Firmware Login Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in TOTOLINK EX1200T devices that allows unauthenticated attackers to bypass login controls by sending a specific request to the `formLoginAuth.htm` page. This could enable unauthorized administrative access to the device, potentially impacting network security. The relevance and exposure

CVE advisoryCRITICAL

CVE-2025-51452

TOTOLINK A7000R Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in TOTOLINK router firmware allows unauthenticated network access to the administrative interface by sending a specific request, bypassing login. This could expose router settings and management functions to unauthorized control if the interface is network-reachable.