PT-2024-24221 · Totolink · Totolink Ex200

Published

2024-04-08

·

Updated

2024-11-19

·

CVE-2024-31813

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX200 version 4.0.3c.7646 B20201211
Description The issue is related to the lack of an authentication mechanism by default. This means that the device does not require users to authenticate before accessing its features, potentially allowing unauthorized access.
Recommendations For TOTOLINK EX200 version 4.0.3c.7646 B20201211, consider configuring an authentication mechanism to restrict access to the device. As a temporary workaround, restrict access to the device's web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-31813

Affected Products

Totolink Ex200