First published: Mon Apr 08 2024(Updated: )
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink EX200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31815 has not been assigned a CVSS score yet, but it poses a significant risk as it allows unauthorized access to sensitive configuration files.
To mitigate CVE-2024-31815, users should update their TOTOLINK EX200 firmware to the latest version released by the vendor.
CVE-2024-31815 is classified as an unauthorized access vulnerability that enables attackers to retrieve configuration files.
CVE-2024-31815 affects the TOTOLINK EX200 version V4.0.3c.7314_B20191204 and potentially other versions if they share the same flaw.
Attackers can exploit CVE-2024-31815 by sending a request to the /cgi-bin/ExportSettings.sh endpoint to obtain the configuration file without necessary authorization.