First published: Wed Mar 30 2022(Updated: )
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3100r Firmware | =5.9c.4577 | |
TOTOLink A3100R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-46010.
The severity of CVE-2021-46010 is high with a CVSS score of 8.8.
The affected software of CVE-2021-46010 is Totolink A3100R V5.9c.4577.
CVE-2021-46010 allows an attacker to hijack a valid session and conduct further malicious operations.
To fix CVE-2021-46010, it is recommended to update to a patched version of Totolink A3100R firmware.