Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0569

Опубликовано: 16 янв. 2024
Источник: nvd
CVSS3: 4.3
CVSS3: 9.1
CVSS2: 4
EPSS Низкий

Описание

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862_B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:t8_firmware:4.1.5cu.833_20220905:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t8:-:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00365
Низкий

4.3 Medium

CVSS3

9.1 Critical

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862_B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability.

EPSS

Процентиль: 58%
0.00365
Низкий

4.3 Medium

CVSS3

9.1 Critical

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-862