First published: Mon Nov 26 2018(Updated: )
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13315 is a vulnerability in TOTOLINK A3002RU version 1.0.8 that allows attackers to change the admin user's password via an unauthenticated POST request.
Attackers can exploit CVE-2018-13315 by sending an unauthenticated POST request to the formPasswordSetup in TOTOLINK A3002RU version 1.0.8 to change the admin user's password.
TOTOLINK A3002RU version 1.0.8 is affected by CVE-2018-13315.
CVE-2018-13315 has a severity score of 9.8 (critical).
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13315.