CVE-2021-34218: Medium severity totolink a3002r firmware vulnerability
Published Aug 20, 2021
·Updated
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
Affected Software
2 affected components
TOTOLINK A3002R Firmware=1.1.1-b20200824
TOTOLINK A3002R
Event History
Aug 20, 2021
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is CVE-2021-34218?
CVE-2021-34218 is a vulnerability in the Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 that allows an attacker to access certain directories.
2
What is the severity of CVE-2021-34218?
The severity of CVE-2021-34218 is medium with a CVSS score of 5.3.
3
How can an attacker exploit CVE-2021-34218?
An attacker can exploit CVE-2021-34218 by accessing the /add/, /img/, /js/, and /mobile directories via GET Parameter.
4
Is TOTOLINK A3002R affected by CVE-2021-34218?
No, TOTOLINK A3002R is not affected by CVE-2021-34218.
5
Where can I find more information about CVE-2021-34218?
You can find more information about CVE-2021-34218 at the following URL: https://github.com/pup2y/IoTVul/tree/main/TOTOLINK/A3002R%20Directory%20Indexing