VulnerabilityModified
CVE-2021-42886
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
HIGH 7.5EPSS 2.10%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.10% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- totolink/ex1200t firmware
- Source
- cve@mitre.org
References
- https://github.com/p1Kk/vuln/blob/main/totolink_ex1200t_exportsettings_leak.mdExploit, Third Party Advisory
- https://github.com/p1Kk/vuln/blob/main/totolink_ex1200t_exportsettings_leak.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.