CVE-2018-13317: XSS
Published Nov 26, 2018
·Updated
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13317?
The severity of CVE-2018-13317 is medium with a CVSS score of 6.1.
2
How can attackers exploit CVE-2018-13317?
Attackers can exploit CVE-2018-13317 by making a GET request for password.htm to obtain the plaintext password for the admin user.
3
What software versions are affected by CVE-2018-13317?
TOTOLINK A3002RU firmware version 1.0.8 is affected by CVE-2018-13317.
4
Is TOTOLINK A3002RU version 1.0.8 vulnerable to CVE-2018-13317?
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13317.
5
How can I fix CVE-2018-13317?
To fix CVE-2018-13317, upgrade the TOTOLINK A3002RU firmware to a version that is not vulnerable.