Critical severity9.8NVD Advisory· Published Aug 15, 2024· Updated Jun 17, 2026
CVE-2024-42967
CVE-2024-42967
Description
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:totolink:lr350_firmware:9.3.5u.6369_b20220309:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/TOTOLINK/LR350/ExportSettings.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.