ZeroHour

CVE-2021-46009

PoC
CVSS 3.1
9.8 critical
EPSS
13%p96
Published
()
Modified
Description

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

Vendors
totolink
Products
a3100r firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.