First published: Mon Nov 26 2018(Updated: )
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13309 is a vulnerability in TOTOLINK A3002RU version 1.0.8 that allows attackers to execute arbitrary JavaScript via the user's password.
CVE-2018-13309 has a severity level of medium with a CVSS score of 6.1.
An attacker can exploit CVE-2018-13309 by injecting arbitrary JavaScript code through the user's password in the password.htm page of TOTOLINK A3002RU version 1.0.8.
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13309.
No, there may be other software versions of TOTOLINK A3002RU that are affected by CVE-2018-13309.