← Vulnerability feed

Vulnerability record · CVE-2024-31817 · published 8 April 2024

CVE-2024-31817: TOTOLINK EX200 getSysStatusCfg unauthenticated information disclosure

TTotolink · Ex200 Firmware

The TOTOLINK EX200 firmware (V4.0.3c.7646_B20201211) exposes sensitive information through the getSysStatusCfg function without requiring authorization. Because the endpoint is reachable over the network with no privileges, any remote party who can reach the device can pull configuration data. This matters for range extenders that are often left on default settings and reachable from the LAN or WAN side.

7.5 CVSS 3.1 High EPSS 55% · top 1.0% CWE-200 · Information exposure
7.5CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote information disclosure with a public exploit and very high EPSS, though no KEV listing or confirmed in-the-wild use is documented.

What it is

The TOTOLINK EX200 firmware (V4.0.3c.7646_B20201211) exposes sensitive information through the getSysStatusCfg function without requiring authorization. Because the endpoint is reachable over the network with no privileges, any remote party who can reach the device can pull configuration data. This matters for range extenders that are often left on default settings and reachable from the LAN or WAN side.

Impact

An attacker gains sensitive device configuration information without authentication, which can expose credentials, network settings or other data useful for follow-on attacks. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality only.

Attack surface

Reached over the network via the getSysStatusCfg function, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Any host that can reach the device's management interface can trigger it.

Exploitation

A public exploit write-up exists (reference tagged Exploit), and EPSS is 0.5534 (99th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Apply the vendor firmware update for TOTOLINK EX200 if one is available; the record does not name a fixed version, so confirm with TOTOLINK.
  • If no patch exists, restrict access to the device management interface to trusted networks only and block it from the WAN.
  • Change default administrative credentials and disable remote management where the device supports it.
  • Segment IoT and range extender devices on a separate VLAN with no access to sensitive internal systems.
  • Monitor vendor advisories for a fixed firmware release and track the device as end-of-support risk if none appears.

Detection

  • Monitor network traffic to the EX200 management interface for requests to the getSysStatusCfg endpoint from unexpected hosts.
  • Alert on access to the device web interface from outside the trusted management VLAN or from WAN-facing addresses.
  • Baseline normal management traffic to the device and flag new or repeated unauthenticated requests to configuration functions.
  • Review device logs, if available, for configuration retrieval events from unknown source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-31817 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-31810Totolink ex200 firmware hard-coded credentials vulnerabilityTOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.EPSS 0.62%9.8CVE-2024-31807Totolink ex200 firmware code injection vulnerabilityTOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync…EPSS 1.4%9.8CVE-2021-43711Totolink ex200 firmware command injection vulnerabilityThe downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The p…EPSS 38%9.1CVE-2024-31815Totolink ex200 firmware insecure direct object reference vulnerabilityIn TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.shEPSS 0.58%8.8CVE-2024-31808Totolink ex200 firmware vulnerabilityTOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWe…EPSS 0.93%8.8CVE-2024-31809Totolink ex200 firmware vulnerabilityTOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgr…EPSS 0.98%8.8CVE-2024-31814Totolink ex200 firmware authentication bypass via alternate path vulnerabilityTOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.EPSS 8.3%8.7CVE-2024-7336Totolink ex200 firmware classic buffer overflow vulnerabilityA vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-31817), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.