Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
Name | Vendor | Start Version | End Version |
---|---|---|---|
N350rt_firmware | Totolink | 9.3.5u.6139_b20201216 (including) | 9.3.5u.6139_b20201216 (including) |