First published: Fri Aug 20 2021(Updated: )
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002r Firmware | =1.1.1-b20200824 | |
TOTOLINK A3002R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-34228.
The severity of CVE-2021-34228 is medium (6.1).
The affected software of CVE-2021-34228 is TOTOLINK A3002R with firmware version 1.1.1-B20200824.
The vulnerability allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field in parent_control.htm.
Yes, TOTOLINK A3002R version V1.1.1-B20200824 is vulnerable to CVE-2021-34228.