First published: Tue Nov 27 2018(Updated: )
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-13314.
The severity level of CVE-2018-13314 is critical with a score of 9.8.
Attackers can exploit this vulnerability by executing system commands through the "ipAddr" POST parameter in the formAliasIp function.
TOTOLINK A3002RU version 1.0.8 is affected by this vulnerability.
Yes, TOTOLINK A3002RU version 1.0.8 is the only affected software.