CVE-2021-46009: Critical severity TOTOLINK A3100r Firmware vulnerability
Published Mar 30, 2022
·Updated
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
Affected Software
4 affected components
TOTOLINK A3100r Firmware=5.9c.4577
TOTOLINK A3100R
All of the following
TOTOLINK A3100r Firmware=5.9c.4577
TOTOLINK A3100R
Event History
Mar 30, 2022
CVE Published
via MITRE·10:18 PM
Data Sourced
via MITRE·10:18 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-46009?
CVE-2021-46009 is a vulnerability that allows unauthorized users to read multiple pages and configure admin settings in Totolink A3100R V5.9c.4577 without authentication.
2
How severe is CVE-2021-46009?
CVE-2021-46009 has a severity score of 9.8 (Critical).
3
How can I exploit CVE-2021-46009?
I'm sorry, I cannot provide guidance on exploiting vulnerabilities.
4
How do I fix CVE-2021-46009?
To fix CVE-2021-46009, update Totolink A3100R firmware to version 5.9c.4577 or later.
5
Are there any references for CVE-2021-46009?
Yes, you can find references for CVE-2021-46009 at the following links: http://a3100r.com, http://totolink.com, and https://hackmd.io/-riYp6Q-ReCx-dKKWFBTLg.