CRITICAL🇵🇱 Wersja polska

CVE-2024-31815

CVSS 9.1v3.1pub. 2024-04-08upd. 2025-06-17

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

🤖 AI Analysis
How it works

An attacker sends an HTTP request directly to the /cgi-bin/ExportSettings.sh endpoint, which does not require any authentication. This script returns the device configuration file without verifying the identity of the requester. The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), which indicates a lack of proper access control to the resource.

Impact

An attacker can obtain the complete device configuration file, which may contain passwords, network keys, and other sensitive data, leading to compromise of confidentiality and integrity of the network environment.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references provided. Until an update is applied, it is recommended to restrict access to the device's administrative interface only to trusted hosts and implement network segmentation to prevent access to the management panel from external sources.

Who is affected

TOTOLINK EX200 with firmware version V4.0.3c.7314_B20191204

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Totolink Ex200

    HW
    Totolink
    all versions
  • Totolink Ex200 Firmware

    OS
    Totolink
    4.0.3c.7646_b20201211
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-31810CRITICAL9.8PL ✓same product

TOTOLINK EX200: zakodowane na stałe hasło roota w firmware

CVE-2024-31807CRITICAL9.8PL ✓same product

RCE w TOTOLINK EX200 poprzez parametr hostTime w funkcji NTPSyncWithHost

CVE-2021-43711CRITICAL9.8PL ✓same product

Command injection w TOTOLINK EX200 — nieuwierzytelnione RCE przez downloadFlile.cgi

CVE-2024-7335HIGH8.7same product

A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the...

CVE-2024-7336HIGH8.7same product

A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vul...