A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273259. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTotolink Ex200
HWTotolinkall versionsTotolink Ex200 Firmware
OSTotolink4.0.3c.7646_b20201211
Related vulnerabilities
TOTOLINK EX200: zakodowane na stałe hasło roota w firmware
TOTOLINK EX200 – nieautoryzowany dostęp do pliku konfiguracyjnego
RCE w TOTOLINK EX200 poprzez parametr hostTime w funkcji NTPSyncWithHost
Command injection w TOTOLINK EX200 — nieuwierzytelnione RCE przez downloadFlile.cgi
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the...