First published: Tue Oct 31 2023(Updated: )
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
=17.0.0cu.557_b20221024 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-46992 is high with a CVSS score of 7.5.
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control, allowing attackers to reset critical passwords without authentication.
The affected software version for CVE-2023-46992 is Totolink A3300R Firmware V17.0.0cu.557_B20221024.
Yes, attackers can reset critical passwords without authentication on TOTOLINK A3300R V17.0.0cu.557_B20221024.
To fix CVE-2023-46992, it is recommended to install the latest firmware update provided by Totolink.