In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.