ZeroHour

CVE-2018-13311

CVSS 3.0
9.8 critical
EPSS
2%p84
Published
()
Modified
Description

System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.

Vendors
totolink
Products
a3002ru firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.