CVE-2024-31805: Medium severity totolink ex200 vulnerability
Published Apr 8, 2024
·Updated
TOTOLINK EX200 V4.0.3c.7646B20201211 allows attackers to start the Telnet service without authorization via the telnetenabled parameter in the setTelnetCfg function.
Affected Software
3 affected components
TOTOLINK EX200
All of the following
TOTOLINK Ex200 Firmware=4.0.3c.7646_b20201211
TOTOLINK EX200
Event History
Apr 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31805?
CVE-2024-31805 has a medium severity rating due to the potential for unauthorized access to the Telnet service.
2
How do I fix CVE-2024-31805?
To fix CVE-2024-31805, disable the Telnet service on the TOTOLINK EX200 device if it is not needed.
3
What impact does CVE-2024-31805 have on the TOTOLINK EX200?
CVE-2024-31805 allows attackers to enable the Telnet service without authorization, potentially compromising the device.
4
Is CVE-2024-31805 being actively exploited?
There is no current evidence suggesting that CVE-2024-31805 is being widely exploited in the wild.
5
What versions of TOTOLINK EX200 are affected by CVE-2024-31805?
CVE-2024-31805 affects the TOTOLINK EX200 running firmware version V4.0.3c.7646_B20201211.