CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-31814

Medium Severity|Totolink
38
SVRS
8.8
CVSSv3
0.08567
EPSS
TAGS
In The WildExploit Available
VECTOR STRING
CVSS:3.1AV:AAC:LPR:NUI:NS:UC:HI:HA:H
PUBLICATION DATE2024-04-08
LAST MODIFIED2024-08-02

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-31814, is a login bypass flaw affecting the TOTOLINK EX200 wireless extender. It allows attackers to circumvent the authentication mechanism through the `Form_Login` function. This matters significantly because successful exploitation grants unauthorized access to the device, potentially leading to full control over the network it serves. Such unauthorized access can compromise network security, data integrity, and device availability, posing a severe risk to users and connected systems.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for CVE-2024-31814 is 8.8. This score indicates a High severity level. The vulnerability was publicly published on April 8, 2024, at 00:00:00 UTC and was last modified on August 2, 2024, at 01:59:50 UTC.
3. Which products, vendors, systems, and versions are affected?
  • Vendor: TOTOLINK
  • Product: EX200 wireless extender
  • Affected Version: V4.0.3c.7646_B20201211
4. What is the technical root cause and attack vector?
The technical root cause of this vulnerability is an improper authentication mechanism, specifically categorized under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The attack vector involves exploiting a weakness within the `Form_Login` function of the TOTOLINK EX200 firmware. Attackers can craft specific requests to this function to bypass the login process and gain unauthorized access to the device's administrative interface.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker sending specially crafted requests to the `Form_Login` function on the vulnerable TOTOLINK EX200 device. By manipulating parameters or sequences of requests to this function, an attacker can bypass the intended authentication checks, thereby gaining administrative access to the device without valid credentials. The exploitation likely occurs over the network, targeting the device's web management interface.
6. What mitigation steps and patches are available?
The provided CVE data does not explicitly detail specific mitigation steps or the availability of patches from the vendor (TOTOLINK) to address CVE-2024-31814. Users are advised to monitor official TOTOLINK channels for firmware updates that address this vulnerability. In the absence of an official patch, temporary mitigation might involve restricting network access to the device's management interface to trusted hosts only or isolating the device on a segmented network if its functionality permits.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying TOTOLINK EX200 devices running the specific firmware version V4.0.3c.7646_B20201211. Detection methods include:
  • Firmware Version Check: Accessing the device's web management interface (if accessible) to check the installed firmware version.
  • Network Scanning: Using network scanning tools to identify TOTOLINK EX200 devices and potentially infer their firmware version through banners or other network-identifiable attributes, although this might be less precise.
  • Asset Inventory: Consulting existing asset management systems or inventories for deployed TOTOLINK EX200 devices and their firmware versions.
8. What are the indicators of compromise (IOCs)?
The provided CVE data does not specify direct Indicators of Compromise (IOCs) for CVE-2024-31814. However, general IOCs related to an exploited login bypass on a network device could include:
  • Unauthorized login attempts or successful logins from unknown IP addresses in device logs.
  • Unexpected configuration changes on the TOTOLINK EX200 device.
  • Unusual network traffic patterns originating from or passing through the EX200.
  • New or modified administrator accounts.
Monitoring device logs and network traffic for anomalies is crucial.
9. Which threat actors are known to exploit this vulnerability?
The provided CVE data does not specify any particular threat actors known to be actively exploiting CVE-2024-31814. However, vulnerabilities with a high CVSS score and straightforward exploitation methods like login bypass are often quickly adopted by various threat actors, ranging from opportunistic attackers to more sophisticated groups, for initial access to networks.
10. What public intelligence references and advisories exist?
The primary public intelligence reference for this vulnerability is the CVE entry itself: CVE-2024-31814. This entry serves as the official identifier and source of basic information regarding the vulnerability, including its description, severity, and affected products. Further details might be available from the CVE Numbering Authority (CNA) that assigned this CVE, security research blogs, or vendor advisories if released subsequent to the CVE publication.
11. What is the risk assessment and urgency level?
Risk Assessment: The risk associated with CVE-2024-31814 is assessed as High. This is due to its CVSS score of 8.8, indicating a severe vulnerability. The ability to bypass login controls directly leads to unauthorized administrative access, which can allow an attacker to completely compromise the device, manipulate network settings, or pivot into other parts of the network. This could result in data theft, denial of service, or the use of the device as a platform for further attacks.

Urgency Level: The urgency level for addressing this vulnerability is High. Organizations and individuals using the affected TOTOLINK EX200 V4.0.3c.7646_B20201211 firmware should take immediate action to assess their exposure and implement any available mitigations or patches to prevent exploitation.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

Configuration 1
TypeVendorProduct
OSTotolinkex200_firmware
ReferenceLink
INTHEWILDhttps://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Login_Bypass/bypass.md
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Login_Bypass/bypass.md
[email protected]https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Login_Bypass/bypass.md
[email protected]https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Login_Bypass/bypass.md
INTHEWILDhttps://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Login_Bypass/bypass.md
CWE IDCWE NameDescription
CWE-288Authentication Bypass Using an Alternate Path or ChannelA product requires authentication, but the product has an alternate path or channel that does not require authentication.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.