# TOTOLINK EX200 Obtain Sensitive Information (/ExportSettings.sh) ## Description In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the apmib configuration file without authorization through /cgi-bin/ExportSettings.sh ## TOTOLINK EX200 version information - Device:TOTOLINK EX200 - Firmware Version:V4.0.3c.7646_B20201211 - Manufacturer's website information:https://www.totolink.net/ - Firmware download address:https://www.totolink.net/data/upload/20210428/7979e841521515eb83b45aacf5b67f9a.zip ## Vulnerability information When making a request to `/cgi-bin/ExportSettings.sh`, the attacker can obtain the `apmib` configuration file Config-EX200-xxxxxxxx.dat without authorization. The username and password can be found in the decoded file. ![](1.png)