First published: Mon Nov 26 2018(Updated: )
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13310 is a vulnerability in TOTOLINK A3002RU version 1.0.8 that allows attackers to execute arbitrary JavaScript via the user's username.
CVE-2018-13310 has a severity rating of medium, with a score of 6.1.
TOTOLINK A3002RU version 1.0.8 is affected by CVE-2018-13310.
An attacker can exploit CVE-2018-13310 by injecting arbitrary JavaScript through the user's username in the password.htm page of TOTOLINK A3002RU version 1.0.8.
Yes, TOTOLINK A3002RU version 1.0.8 is the only affected software version by CVE-2018-13310.