PT-2024-24223 · Totolink · Totolink Ex200

Published

2024-04-03

·

Updated

2025-06-17

·

CVE-2024-31815

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK EX200 version 4.0.3c.7314 B20191204
Description An attacker can obtain the configuration file without authorization through the "/cgi-bin/ExportSettings.sh" API endpoint.
Recommendations For TOTOLINK EX200 version 4.0.3c.7314 B20191204, as a temporary workaround, consider restricting access to the "/cgi-bin/ExportSettings.sh" API endpoint until a patch is available.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2025-11316
CVE-2024-31815

Affected Products

Totolink Ex200