PT-2021-20404 · Totolink · Totolink A3002Ru
Published
2021-08-20
·
Updated
2021-08-26
·
CVE-2021-34223
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
TOTOLINK A3002R version V1.1.1-B20200824
Description:
Cross-site scripting in urlfilter.htm allows attackers to execute arbitrary JavaScript by modifying the
URL Address field. This issue enables attackers to execute arbitrary JavaScript code, potentially leading to unauthorized actions on the affected system.Recommendations:
For TOTOLINK A3002R version V1.1.1-B20200824, as a temporary workaround, consider restricting access to the urlfilter.htm page until a patch is available. Avoid using the
URL Address field in the affected page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink A3002Ru