PT-2024-30228 · Totolink · Totolink Lr350

Published

2024-08-15

·

Updated

2024-09-06

·

CVE-2024-42967

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK LR350 version 9.3.5u.6369 B20220309
Description The issue is related to incorrect access control, allowing attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to "/cgi-bin/ExportSettings.sh". This exposes usernames and passwords to attackers, posing a serious threat.
Recommendations For TOTOLINK LR350 version 9.3.5u.6369 B20220309, update your system to prevent unauthorized access. As a temporary workaround, consider restricting access to the "/cgi-bin/ExportSettings.sh" endpoint until a patch is available.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42967

Affected Products

Totolink Lr350