PT-2024-30228 · Totolink · Totolink Lr350
Published
2024-08-15
·
Updated
2024-09-06
·
CVE-2024-42967
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TOTOLINK LR350 version 9.3.5u.6369 B20220309
Description
The issue is related to incorrect access control, allowing attackers to obtain the apmib configuration file, which contains the
username and the password, via a crafted request to "/cgi-bin/ExportSettings.sh". This exposes usernames and passwords to attackers, posing a serious threat.Recommendations
For TOTOLINK LR350 version 9.3.5u.6369 B20220309, update your system to prevent unauthorized access. As a temporary workaround, consider restricting access to the "/cgi-bin/ExportSettings.sh" endpoint until a patch is available.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink Lr350