PT-2024-1361 · Totolink · Totolink N200Re

Chun-Li Lin

+1

·

Published

2024-01-26

·

Updated

2024-05-17

·

CVE-2024-0942

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Totolink N200RE V5 version 9.3.5u.6255 B20211224
Description The issue is related to the /cgi-bin/cstecgi.cgi file in the Totolink N200RE router's firmware, specifically concerning incorrect session expiration. This can allow a remote attacker to disclose protected information. The manipulation of an unknown function in the file leads to session expiration, and it is possible to launch the attack remotely.
Recommendations For Totolink N200RE V5 version 9.3.5u.6255 B20211224, consider restricting access to the /cgi-bin/cstecgi.cgi file as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2024-00815
CVE-2024-0942

Affected Products

Totolink N200Re