In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
An attacker sends an HTTP request directly to the /cgi-bin/ExportSettings.sh endpoint, which does not require any authentication. This script returns the device configuration file without verifying the identity of the requester. The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), which indicates a lack of proper access control to the resource.
An attacker can obtain the complete device configuration file, which may contain passwords, network keys, and other sensitive data, leading to compromise of confidentiality and integrity of the network environment.
Patches available from the manufacturer should be applied according to the references provided. Until an update is applied, it is recommended to restrict access to the device's administrative interface only to trusted hosts and implement network segmentation to prevent access to the management panel from external sources.
TOTOLINK EX200 with firmware version V4.0.3c.7314_B20191204
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NTotolink Ex200
HWTotolinkall versionsTotolink Ex200 Firmware
OSTotolink4.0.3c.7646_b20201211
Related vulnerabilities
TOTOLINK EX200: zakodowane na stałe hasło roota w firmware
RCE w TOTOLINK EX200 poprzez parametr hostTime w funkcji NTPSyncWithHost
Command injection w TOTOLINK EX200 — nieuwierzytelnione RCE przez downloadFlile.cgi
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the...
A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vul...