First published: Wed Mar 30 2022(Updated: )
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3100r Firmware | =5.9c.4577 | |
TOTOLink A3100R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46009 is a vulnerability that allows unauthorized users to read multiple pages and configure admin settings in Totolink A3100R V5.9c.4577 without authentication.
CVE-2021-46009 has a severity score of 9.8 (Critical).
I'm sorry, I cannot provide guidance on exploiting vulnerabilities.
To fix CVE-2021-46009, update Totolink A3100R firmware to version 5.9c.4577 or later.
Yes, you can find references for CVE-2021-46009 at the following links: http://a3100r.com, http://totolink.com, and https://hackmd.io/-riYp6Q-ReCx-dKKWFBTLg.