PT-2022-12502 · Totolink · Totolink A3100R
Kv
·
Published
2022-03-30
·
Updated
2022-04-05
·
CVE-2021-46010
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Totolink A3100R version 5.9c.4577
Description
The issue concerns the use of insufficiently random values via the web configuration, making the
SESSION ID predictable. This predictability allows an attacker to hijack a valid session and conduct further malicious operations.Recommendations
For Totolink A3100R version 5.9c.4577, consider restricting access to the web configuration until a patch is available to minimize the risk of session hijacking. As a temporary workaround, avoid using the predictable
SESSION ID in the affected web configuration endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink A3100R