CVE-2018-13315: Input Validation
Published Nov 26, 2018
·Updated
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13315?
CVE-2018-13315 is a vulnerability in TOTOLINK A3002RU version 1.0.8 that allows attackers to change the admin user's password via an unauthenticated POST request.
2
How can attackers exploit CVE-2018-13315?
Attackers can exploit CVE-2018-13315 by sending an unauthenticated POST request to the formPasswordSetup in TOTOLINK A3002RU version 1.0.8 to change the admin user's password.
3
Which version of TOTOLINK A3002RU is affected by CVE-2018-13315?
TOTOLINK A3002RU version 1.0.8 is affected by CVE-2018-13315.
4
What is the severity of CVE-2018-13315?
CVE-2018-13315 has a severity score of 9.8 (critical).
5
Is TOTOLINK A3002RU version 1.0.8 vulnerable to CVE-2018-13315?
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13315.