CVE-2024-42966: Critical severity totolink n350rt firmware vulnerability
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42966?
CVE-2024-42966 is considered a high severity vulnerability due to its ability to expose sensitive configuration information.
How do I fix CVE-2024-42966?
To fix CVE-2024-42966, update the TOTOLINK N350RT firmware to a version that addresses this access control issue.
What types of information can be exposed due to CVE-2024-42966?
CVE-2024-42966 can expose the apmib configuration file, which contains critical information like usernames and passwords.
Who is affected by CVE-2024-42966?
Users of the TOTOLINK N350RT running firmware version 9.3.5u.6139_B20201216 are affected by CVE-2024-42966.
Can CVE-2024-42966 be exploited remotely?
Yes, CVE-2024-42966 can be exploited remotely via crafted requests to the affected device's CGI script.