CVE-2024-0569: Totolink T8 Setting cstecgi.cgi getSysStatusCfg information disclosure
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.83320220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0569?
CVE-2024-0569 is classified as problematic and poses a risk of information disclosure.
How do I fix CVE-2024-0569?
To mitigate CVE-2024-0569, you should update your Totolink T8 firmware to a version that addresses this vulnerability.
What products are affected by CVE-2024-0569?
CVE-2024-0569 affects the Totolink T8 firmware version 4.1.5cu.833_20220905.
What type of attack does CVE-2024-0569 enable?
CVE-2024-0569 enables an attacker to manipulate certain parameters for information disclosure.
Is CVE-2024-0569 related to the Setting Handler component?
Yes, CVE-2024-0569 specifically affects the Setting Handler component in the Totolink T8 device.