PT-2024-24222 · Totolink · Totolink Ex200

Published

2024-04-03

·

Updated

2024-08-01

·

CVE-2024-31814

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX200 version 4.0.3c.7646 B20201211
Description The issue allows attackers to bypass login through the Form Login function.
Recommendations For TOTOLINK EX200 version 4.0.3c.7646 B20201211, as a temporary workaround, consider disabling the Form Login function until a patch is available.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2025-03201
CVE-2024-31814

Affected Products

Totolink Ex200