9.8
CVSSv3

CVE-2018-13315

Published: 26/11/2018 Updated: 20/12/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows malicious users to change the admin user's password via an unauthenticated POST request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

totolink a3002ru_firmware 1.0.8