First published: Tue Nov 27 2018(Updated: )
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-13306.
The severity of CVE-2018-13306 is critical with a score of 9.8.
TOTOLINK A3002RU firmware version 1.0.8 is affected by CVE-2018-13306.
An attacker can exploit CVE-2018-13306 by executing system commands through the "ftpUser" POST parameter in the formDlna function of TOTOLINK A3002RU version 1.0.8.
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13306.