PT-2020-7921 · Totolink · Totolink A850R-V1+1

Alexandre Torres

+2

·

Published

2020-11-24

·

Updated

2020-12-04

·

CVE-2015-9550

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: TOTOLINK A850R-V1 versions 1.0.1-B20150707.1612 and earlier TOTOLINK F1-V2 versions 1.1-B20150708.1646 and earlier
Description: An issue allows the web management interface to be opened on the WAN interface by sending a specific hel,xasf packet.
Recommendations: For TOTOLINK A850R-V1 versions 1.0.1-B20150707.1612 and earlier, restrict access to the WAN interface to prevent exploitation. For TOTOLINK F1-V2 versions 1.1-B20150708.1646 and earlier, consider disabling the web management interface on the WAN interface until a fix is available.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9550

Affected Products

Totolink A850R-V1
Totolink F1-V2