PT-2026-47632 · Totolink · Ex200

L-14

·

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-11620

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Exploit

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2026-11620

Affected Products

Ex200