CVE-2018-13311: OS Command Injection
Published Nov 26, 2018
·Updated
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2018-13311
2
What is the affected software for this vulnerability?
Totolink A3002ru Firmware version 1.0.8
3
What is the severity of CVE-2018-13311?
The severity of CVE-2018-13311 is critical with a CVSS score of 9.8.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by executing system commands through the "sambaUser" POST parameter in the formDlna.
5
Is there a fix available for this vulnerability?
Yes, the vendor has released a fix to address the vulnerability in Totolink A3002ru Firmware version 1.0.8.