CVE-2021-43661: XSS
totolink EX300v2 V4.0.3c.140B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43661?
CVE-2021-43661 is a reflected cross-site scripting (XSS) vulnerability in totolink EX300_v2 V4.0.3c.140_B20210429 firmware.
How does CVE-2021-43661 affect totolink EX300_v2?
CVE-2021-43661 allows an attacker to inject malicious code into the /home.asp component of totolink EX300_v2 firmware, leading to potential remote code execution or unauthorized access to sensitive information.
What is the severity of CVE-2021-43661?
CVE-2021-43661 has a severity score of 6.1, which is classified as medium.
How can I fix CVE-2021-43661?
To fix CVE-2021-43661, it is recommended to update the totolink EX300_v2 firmware to a version that addresses the XSS vulnerability.
Where can I find more information about CVE-2021-43661?
More information about CVE-2021-43661 can be found at the following reference: [link](https://github.com/chibataiki/iot-vuls/blob/main/totolink/xss-vulnerability.md).