First published: Fri Aug 20 2021(Updated: )
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002r Firmware | =1.1.1-b20200824 | |
TOTOLINK A3002R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34218 is a vulnerability in the Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 that allows an attacker to access certain directories.
The severity of CVE-2021-34218 is medium with a CVSS score of 5.3.
An attacker can exploit CVE-2021-34218 by accessing the /add/, /img/, /js/, and /mobile directories via GET Parameter.
No, TOTOLINK A3002R is not affected by CVE-2021-34218.
You can find more information about CVE-2021-34218 at the following URL: https://github.com/pup2y/IoTVul/tree/main/TOTOLINK/A3002R%20Directory%20Indexing