First published: Mon Nov 26 2018(Updated: )
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the cross-site scripting in TOTOLINK A3002RU version 1.0.8 is CVE-2018-13308.
The severity rating of CVE-2018-13308 is medium.
An attacker can exploit the CVE-2018-13308 vulnerability by modifying the "User phrases button" field to execute arbitrary JavaScript.
The vulnerability affects TOTOLINK A3002RU version 1.0.8.
Yes, TOTOLINK A3002RU version 1.0.8 is the only vulnerable version.