ZeroHour

CVE-2018-13315

PoC
CVSS 3.0
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.

Vendors
totolink
Products
a3002ru firmware
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.