Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
2024-08-15T17:15:20.130
2024-10-24T20:35:08.087
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | n350rt_firmware | 9.3.5u.6139_b20201216 | Yes |
Hardware | totolink | n350rt | - | No |