ZeroHour

CVE-2018-13307

PoC
CVSS 3.0
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.

Vendors
totolink
Products
a3002ru firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.