Skip to content

Latest commit

 

History

History
17 lines (11 loc) · 724 Bytes

File metadata and controls

17 lines (11 loc) · 724 Bytes

TOTOLINK EX200 Obtain Sensitive Information (getEasyWizardCfg)

Description

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

TOTOLINK EX200 version information

Vulnerability information

The attacker does not need authorization (no need to enter username and password in /login.asp) to obtain sensitive information including Wifi SSID and password.