CVE-2021-46010: High severity TOTOLINK A3100r Firmware vulnerability
Published Mar 30, 2022
·Updated
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSIONID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
Affected Software
4 affected components
TOTOLINK A3100r Firmware=5.9c.4577
TOTOLINK A3100R
All of the following
TOTOLINK A3100r Firmware=5.9c.4577
TOTOLINK A3100R
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Totolink A3100Rto a version that resolves this vulnerability.Fixed in V5.9c.4577
Event History
Mar 30, 2022
CVE Published
via MITRE·10:09 PM
Data Sourced
via MITRE·10:09 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-46010.
2
What is the severity of CVE-2021-46010?
The severity of CVE-2021-46010 is high with a CVSS score of 8.8.
3
What is the affected software ofCVE-2021-46010?
The affected software of CVE-2021-46010 is Totolink A3100R V5.9c.4577.
4
What is the impact of CVE-2021-46010?
CVE-2021-46010 allows an attacker to hijack a valid session and conduct further malicious operations.
5
How can I fix CVE-2021-46010?
To fix CVE-2021-46010, it is recommended to update to a patched version of Totolink A3100R firmware.