PT-2021-20404 · Totolink · Totolink A3002Ru

Published

2021-08-20

·

Updated

2021-08-26

·

CVE-2021-34223

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: TOTOLINK A3002R version V1.1.1-B20200824
Description: Cross-site scripting in urlfilter.htm allows attackers to execute arbitrary JavaScript by modifying the URL Address field. This issue enables attackers to execute arbitrary JavaScript code, potentially leading to unauthorized actions on the affected system.
Recommendations: For TOTOLINK A3002R version V1.1.1-B20200824, as a temporary workaround, consider restricting access to the urlfilter.htm page until a patch is available. Avoid using the URL Address field in the affected page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34223

Affected Products

Totolink A3002Ru