Total
46 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-13315 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2018-12-20 | 5.0 MEDIUM | 9.8 CRITICAL |
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request. | |||||
CVE-2018-13317 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2018-12-20 | 4.3 MEDIUM | 6.1 MEDIUM |
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm. | |||||
CVE-2018-13312 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2018-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field. | |||||
CVE-2018-13308 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2018-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field. | |||||
CVE-2018-13309 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2018-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password. | |||||
CVE-2018-13310 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2018-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username. |