First published: Tue Mar 12 2024(Updated: )
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A8000ru Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28338 has been classified as a high severity vulnerability due to the potential for unauthorized administrative access.
To mitigate CVE-2024-28338, ensure that you update the TOTOLINK A8000RU firmware to the latest version provided by the vendor.
CVE-2024-28338 allows attackers to bypass login mechanisms and gain access to Administrator accounts via a crafted session cookie.
CVE-2024-28338 specifically affects the TOTOLINK A8000RU router running version V7.1cu.643_B20200521.
Yes, CVE-2024-28338 is considered remotely exploitable, allowing attackers to gain unauthorized access without physical access to the device.