PT-2020-7921 · Totolink · Totolink A850R-V1+1
Alexandre Torres
+2
·
Published
2020-11-24
·
Updated
2020-12-04
·
CVE-2015-9550
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
TOTOLINK A850R-V1 versions 1.0.1-B20150707.1612 and earlier
TOTOLINK F1-V2 versions 1.1-B20150708.1646 and earlier
Description:
An issue allows the web management interface to be opened on the WAN interface by sending a specific
hel,xasf packet.Recommendations:
For TOTOLINK A850R-V1 versions 1.0.1-B20150707.1612 and earlier, restrict access to the WAN interface to prevent exploitation.
For TOTOLINK F1-V2 versions 1.1-B20150708.1646 and earlier, consider disabling the web management interface on the WAN interface until a fix is available.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink A850R-V1
Totolink F1-V2