ID

VAR-202401-0374


CVE

CVE-2024-0569


TITLE

TOTOLINK  of  T8  Lack of Authentication Vulnerability in Firmware

Trust: 0.8

sources: JVNDB: JVNDB-2024-001562

DESCRIPTION

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862_B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability. TOTOLINK of T8 A lack of authentication vulnerability exists in the firmware.Information may be obtained and information may be tampered with. TOTOLINK T8 is a wireless dual-band router from China's TOTOLINK Electronics. The vulnerability is caused by the insufficient protection of sensitive information by the parameter ssid/key in the file /cgi-bin/cstecgi.cgi. Attackers can exploit this vulnerability to obtain sensitive information

Trust: 2.16

sources: NVD: CVE-2024-0569 // JVNDB: JVNDB-2024-001562 // CNVD: CNVD-2025-15331

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-15331

AFFECTED PRODUCTS

vendor:totolinkmodel:t8scope:eqversion:4.1.5cu.833_20220905

Trust: 1.0

vendor:totolinkmodel:t8scope: - version: -

Trust: 0.8

vendor:totolinkmodel:t8scope:eqversion: -

Trust: 0.8

vendor:totolinkmodel:t8scope:eqversion:t8 firmware 4.1.5cu.833 20220905

Trust: 0.8

vendor:totolinkmodel:t8 4.1.5cu.833 20220905scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-15331 // JVNDB: JVNDB-2024-001562 // NVD: CVE-2024-0569

CVSS

SEVERITY

CVSSV2

CVSSV3

cna@vuldb.com: CVE-2024-0569
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2024-0569
value: CRITICAL

Trust: 1.0

OTHER: JVNDB-2024-001562
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2025-15331
value: MEDIUM

Trust: 0.6

cna@vuldb.com: CVE-2024-0569
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

OTHER: JVNDB-2024-001562
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2025-15331
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

cna@vuldb.com: CVE-2024-0569
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2024-0569
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: JVNDB-2024-001562
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-15331 // JVNDB: JVNDB-2024-001562 // NVD: CVE-2024-0569 // NVD: CVE-2024-0569

PROBLEMTYPE DATA

problemtype:CWE-862

Trust: 1.0

problemtype:CWE-200

Trust: 1.0

problemtype:Lack of authentication (CWE-862) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-001562 // NVD: CVE-2024-0569

EXTERNAL IDS

db:NVDid:CVE-2024-0569

Trust: 3.2

db:VULDBid:250785

Trust: 2.4

db:JVNDBid:JVNDB-2024-001562

Trust: 0.8

db:CNVDid:CNVD-2025-15331

Trust: 0.6

sources: CNVD: CNVD-2025-15331 // JVNDB: JVNDB-2024-001562 // NVD: CVE-2024-0569

REFERENCES

url:https://vuldb.com/?id.250785

Trust: 2.4

url:https://drive.google.com/file/d/1wswrgekukvpk8hq1vrng-wbr7t6ckngy/view?usp=sharing

Trust: 1.8

url:https://vuldb.com/?ctiid.250785

Trust: 1.0

url:https://vuldb.com/?submit.263653

Trust: 1.0

url:https://www.chtsecurity.com/news/8aa31e69-1e7c-4186-8554-7d5d6baeaa84

Trust: 1.0

url:https://www.chtsecurity.com/news/8f270890-12cc-4623-99a3-a81e00758c29

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-0569

Trust: 0.8

sources: CNVD: CNVD-2025-15331 // JVNDB: JVNDB-2024-001562 // NVD: CVE-2024-0569

SOURCES

db:CNVDid:CNVD-2025-15331
db:JVNDBid:JVNDB-2024-001562
db:NVDid:CVE-2024-0569

LAST UPDATE DATE

2025-07-10T22:47:09.712000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-15331date:2025-07-09T00:00:00
db:JVNDBid:JVNDB-2024-001562date:2024-06-03T06:49:00
db:NVDid:CVE-2024-0569date:2024-06-18T13:21:16.393

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-15331date:2025-07-09T00:00:00
db:JVNDBid:JVNDB-2024-001562date:2024-02-05T00:00:00
db:NVDid:CVE-2024-0569date:2024-01-16T13:15:08.113