CVE-2024-7156: TOTOLINK A3700R apmib Configuration ExportSettings.sh information disclosure
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of the component apmib Configuration Handler. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272570 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7156?
CVE-2024-7156 is classified as problematic due to the potential for information disclosure.
How do I fix CVE-2024-7156?
To mitigate CVE-2024-7156, update to a firmware version that addresses this vulnerability.
What component is affected by CVE-2024-7156?
The affected component in CVE-2024-7156 is the apmib Configuration Handler within the /cgi-bin/ExportSettings.sh file.
Which products are impacted by CVE-2024-7156?
CVE-2024-7156 specifically affects the Totolink A3700R running firmware version 9.1.2u.5822_B20200513.
What are the consequences of exploiting CVE-2024-7156?
Exploiting CVE-2024-7156 could lead to unauthorized information disclosure from the affected device.