In TOTOLINK EX200 V4.0.3c.7646B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
In TOTOLINK EX200 V4.0.3c.7646B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
TOTOLINK EX200 V4.0.3c.7646B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
TOTOLINK EX200 V4.0.3c.7646B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
TOTOLINK EX200 V4.0.3c.7646B20201211 does not contain an authentication mechanism by default.
TOTOLINK EX200 V4.0.3c.7646B20201211 allows attackers to bypass login through the FormLogin function.
TOTOLINK EX200 V4.0.3c.7646B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.