Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
2024-08-15T17:15:20.273
2025-03-13T16:15:22.130
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | lr350_firmware | 9.3.5u.6369_b20220309 | Yes |
Hardware | totolink | lr350 | - | No |