CVE-2024-31815: Critical severity totolink ex200 vulnerability
In TOTOLINK EX200 V4.0.3c.7314B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31815?
CVE-2024-31815 has not been assigned a CVSS score yet, but it poses a significant risk as it allows unauthorized access to sensitive configuration files.
How do I fix CVE-2024-31815?
To mitigate CVE-2024-31815, users should update their TOTOLINK EX200 firmware to the latest version released by the vendor.
What type of vulnerability is CVE-2024-31815?
CVE-2024-31815 is classified as an unauthorized access vulnerability that enables attackers to retrieve configuration files.
Which products are affected by CVE-2024-31815?
CVE-2024-31815 affects the TOTOLINK EX200 version V4.0.3c.7314_B20191204 and potentially other versions if they share the same flaw.
How can attackers exploit CVE-2024-31815?
Attackers can exploit CVE-2024-31815 by sending a request to the /cgi-bin/ExportSettings.sh endpoint to obtain the configuration file without necessary authorization.