CVE-2018-13309: XSS
Published Nov 26, 2018
·Updated
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13309?
CVE-2018-13309 is a vulnerability in TOTOLINK A3002RU version 1.0.8 that allows attackers to execute arbitrary JavaScript via the user's password.
2
How severe is CVE-2018-13309?
CVE-2018-13309 has a severity level of medium with a CVSS score of 6.1.
3
How can an attacker exploit CVE-2018-13309?
An attacker can exploit CVE-2018-13309 by injecting arbitrary JavaScript code through the user's password in the password.htm page of TOTOLINK A3002RU version 1.0.8.
4
Is TOTOLINK A3002RU version 1.0.8 vulnerable to CVE-2018-13309?
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13309.
5
Is TOTOLINK A3002RU version 1.0.8 the only affected software?
No, there may be other software versions of TOTOLINK A3002RU that are affected by CVE-2018-13309.