Critical severity9.8NVD Advisory· Published Aug 15, 2024· Updated Jun 17, 2026
CVE-2024-42966
CVE-2024-42966
Description
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:totolink:n350rt_firmware:9.3.5u.6139_b20201216:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/TOTOLINK/N350R/ExportSettings.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.