CVE-2020-27368: Medium severity totolink a702r-v3 vulnerability
Published Jan 14, 2021
·Updated
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.
Affected Software
2 affected components
TOTOLINK A702r Firmware=1.0.0-b20161227.1023
TOTOLINK A702R
Event History
Jan 14, 2021
CVE Published
via MITRE·03:57 PM
Data Sourced
via MITRE·03:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-27368?
The severity of CVE-2020-27368 is medium with a severity value of 5.5.
2
How does CVE-2020-27368 allow an attacker to access directories?
CVE-2020-27368 allows an attacker to access /icons/ directories via GET Parameter.
3
Which software version is affected by CVE-2020-27368?
The Totolink A702r Firmware version 1.0.0-b20161227.1023 is affected by CVE-2020-27368.
4
Is Totolink A702r vulnerable to CVE-2020-27368?
No, Totolink A702r is not vulnerable to CVE-2020-27368.
5
How can I fix CVE-2020-27368?
To fix CVE-2020-27368, it is recommended to apply the latest firmware update provided by Totolink for A702r.