First published: Wed Mar 30 2022(Updated: )
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Ex300 V2 Firmware | =4.0.3c.140_b20210429 | |
Totolink Ex300 V2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43661 is a reflected cross-site scripting (XSS) vulnerability in totolink EX300_v2 V4.0.3c.140_B20210429 firmware.
CVE-2021-43661 allows an attacker to inject malicious code into the /home.asp component of totolink EX300_v2 firmware, leading to potential remote code execution or unauthorized access to sensitive information.
CVE-2021-43661 has a severity score of 6.1, which is classified as medium.
To fix CVE-2021-43661, it is recommended to update the totolink EX300_v2 firmware to a version that addresses the XSS vulnerability.
More information about CVE-2021-43661 can be found at the following reference: [link](https://github.com/chibataiki/iot-vuls/blob/main/totolink/xss-vulnerability.md).