PT-2024-3093 · Totolink · Totolink Ex200

Published

2024-04-18

·

Updated

2024-07-03

·

CVE-2024-32325

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK EX200 version 4.0.3c.7646 B20201211
Description The issue is related to a Cross-site scripting (XSS) vulnerability. This vulnerability exists due to inadequate protection of the web page structure in the setWiFiExtenderConfig function. The ssid parameter is specifically mentioned as the vulnerable point. Exploitation of this issue may allow a remote attacker to conduct an XSS attack.
Recommendations For TOTOLINK EX200 version 4.0.3c.7646 B20201211, consider disabling the setWiFiExtenderConfig function or restricting access to the ssid parameter until a patch is available. As a temporary workaround, avoid using the ssid parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-03290
CVE-2024-32325

Affected Products

Totolink Ex200