CVE-2024-31815: Totolink EX200 Firmware

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

Affected products

  • Totolink EX200 Firmware: version 4.0.3c.7646_b20201211 only

Published 2024-04-08. Last modified 2026-06-17.