CVE-2021-42893Missing Authentication for Critical Function in Ex1200t Firmware

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateJun 4

Description

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDtotolink/ex1200t_firmware4.1.2cu.5215

🔴Vulnerability Details

2
GHSA
GHSA-h3jm-3m8g-m56v: In TOTOLINK EX1200T V42022-06-04
CVEList
CVE-2021-42893: In TOTOLINK EX1200T V42022-06-03
CVE-2021-42893 — Ex1200t Firmware vulnerability | cvebase