In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-04-08 13:15
Updated : 2024-11-21 09:13
NVD link : CVE-2024-31815
Mitre link : CVE-2024-31815
CVE.ORG link : CVE-2024-31815
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key