PT-2024-24217 · Totolink · Totolink Ex200

Published

2024-04-03

·

Updated

2024-08-01

·

CVE-2024-31809

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX200 version 4.0.3c.7646 B20201211
Description A remote code execution issue was discovered, allowing exploitation via the FileName parameter in the setUpgradeFW function. This enables unauthorized code execution, potentially leading to device compromise.
Recommendations For TOTOLINK EX200 version 4.0.3c.7646 B20201211, consider disabling the setUpgradeFW function until a patch is available to prevent exploitation via the FileName parameter. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-03207
CVE-2024-31809

Affected Products

Totolink Ex200