Totolink N200RE V5 9.3.5u.6255_B20211224 /cgi-bin/cstecgi.cgi session expiration

A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. Using CWE to declare the problem leads to CWE-613. The weakness was released 01/26/2024 by Chun-Li Lin with CHT Security Co., Ltd.. The advisory is available at drive.google.com. This vulnerability is traded as CVE-2024-0942. It is possible to launch the attack remotely. Technical details are available. Furthermore, there is an exploit available. The exploit has been disclosed to the public and may be used. The structure of the vulnerability defines a possible price range of USD $0-$5k at the moment. It is declared as proof-of-concept. The exploit is shared for download at drive.google.com. As 0-day the estimated underground price was around $0-$5k. The vendor was contacted early about this disclosure but did not respond in any way. A possible mitigation has been published even before and not after the disclosure of the vulnerability.

Field02/19/2024 18:2702/19/2024 18:3404/01/2024 08:46
vendorTotolinkTotolinkTotolink
file/cgi-bin/cstecgi.cgi/cgi-bin/cstecgi.cgi/cgi-bin/cstecgi.cgi
cwe613 (session expiration)613 (session expiration)613 (session expiration)
risk222
cvss3_vuldb_avNNN
cvss3_vuldb_acHHH
cvss3_vuldb_prNNN
cvss3_vuldb_uiNNN
cvss3_vuldb_sUUU
cvss3_vuldb_cLLL
cvss3_vuldb_iNNN
cvss3_vuldb_aNNN
cvss3_vuldb_ePPP
cvss3_vuldb_rcRRR
urlhttps://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharinghttps://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharinghttps://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharing
availability111
publicity111
urlhttps://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharinghttps://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharinghttps://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharing
cveCVE-2024-0942CVE-2024-0942CVE-2024-0942
responsibleVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
date1706223600 (01/26/2024)1706223600 (01/26/2024)1706223600 (01/26/2024)
cvss2_vuldb_avNNN
cvss2_vuldb_acHHH
cvss2_vuldb_auNNN
cvss2_vuldb_ciPPP
cvss2_vuldb_iiNNN
cvss2_vuldb_aiNNN
cvss2_vuldb_ePOCPOCPOC
cvss2_vuldb_rcURURUR
cvss2_vuldb_rlNDNDND
cvss3_vuldb_rlXXX
cvss2_vuldb_basescore2.62.62.6
cvss2_vuldb_tempscore2.22.22.2
cvss3_vuldb_basescore3.73.73.7
cvss3_vuldb_tempscore3.43.43.4
cvss3_meta_basescore3.73.93.9
cvss3_meta_tempscore3.43.83.8
nameN200RE V5N200RE V5N200RE V5
version9.3.5u.6255_B202112249.3.5u.6255_B202112249.3.5u.6255_B20211224
videolinkhttps://youtu.be/b0tU2CiLbnUhttps://youtu.be/b0tU2CiLbnUhttps://youtu.be/b0tU2CiLbnU
price_0day$0-$5k$0-$5k$0-$5k
cve_assigned1706223600 (01/26/2024)1706223600 (01/26/2024)1706223600 (01/26/2024)
cve_nvd_summaryA vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
cvss2_nvd_ciPP
cvss2_nvd_iiNN
cvss2_nvd_aiNN
cvss3_cna_avNN
cvss3_cna_acHH
cvss3_cna_prNN
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iNN
cvss3_cna_aNN
cve_cnaVulDBVulDB
cvss2_nvd_basescore2.62.6
cvss3_nvd_basescore4.34.3
cvss3_cna_basescore3.73.7
cvss3_nvd_avNN
cvss3_nvd_acLL
cvss3_nvd_prLL
cvss3_nvd_uiNN
cvss3_nvd_sUU
cvss3_nvd_cLL
cvss3_nvd_iNN
cvss3_nvd_aNN
cvss2_nvd_avNN
cvss2_nvd_acHH
cvss2_nvd_auNN
company_nameCHT Security Co., Ltd.
person_nameChun-Li Lin
person_maillinlic@***********.***
company_websitehttps://www.chtsecurity.com/

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!