First published: Mon Nov 26 2018(Updated: )
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | =1.0.8 | |
TOTOLINK A3002RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-13317 is medium with a CVSS score of 6.1.
Attackers can exploit CVE-2018-13317 by making a GET request for password.htm to obtain the plaintext password for the admin user.
TOTOLINK A3002RU firmware version 1.0.8 is affected by CVE-2018-13317.
Yes, TOTOLINK A3002RU version 1.0.8 is vulnerable to CVE-2018-13317.
To fix CVE-2018-13317, upgrade the TOTOLINK A3002RU firmware to a version that is not vulnerable.