CVE-2018-13306: OS Command Injection
Published Nov 27, 2018
·Updated
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 27, 2018
CVE Published
08:29 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-13306.
2
What is the severity of CVE-2018-13306?
The severity of CVE-2018-13306 is critical with a score of 9.8.
3
Which software versions are affected by CVE-2018-13306?
TOTOLINK A3002RU firmware version 1.0.8 is affected by CVE-2018-13306.
4
How can an attacker exploit CVE-2018-13306?
An attacker can exploit CVE-2018-13306 by executing system commands through the "ftpUser" POST parameter in the formDlna function of TOTOLINK A3002RU version 1.0.8.
5
Is TOTOLINK A3002RU version 1.0.8 vulnerable to CVE-2018-13306?
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13306.