CVE-2024-53333
- EPSS 0.06%
- Published 21.11.2024 18:15:13
- Last modified 04.04.2025 14:40:24
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
CVE-2024-7336
- EPSS 0.28%
- Published 01.08.2024 03:15:01
- Last modified 09.08.2024 14:38:01
A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. ...
CVE-2024-7335
- EPSS 0.2%
- Published 01.08.2024 02:15:02
- Last modified 09.08.2024 14:05:30
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer ove...
CVE-2024-31810
- EPSS 0.59%
- Published 14.05.2024 15:25:45
- Last modified 09.04.2025 14:20:06
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2024-32326
- EPSS 0.17%
- Published 18.04.2024 17:15:48
- Last modified 07.04.2025 14:26:49
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
CVE-2024-32325
- EPSS 0.11%
- Published 18.04.2024 17:15:48
- Last modified 13.05.2025 00:53:54
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.
CVE-2024-31817
- EPSS 10.35%
- Published 08.04.2024 13:15:09
- Last modified 24.03.2025 17:19:53
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
CVE-2024-31814
- EPSS 0.06%
- Published 08.04.2024 13:15:08
- Last modified 18.03.2025 16:03:02
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
CVE-2024-31816
- EPSS 0.11%
- Published 08.04.2024 13:15:08
- Last modified 18.03.2025 16:02:17
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
CVE-2024-31815
- EPSS 0.13%
- Published 08.04.2024 13:15:08
- Last modified 17.06.2025 18:30:45
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh