PT-2022-12502 · Totolink · Totolink A3100R

Kv

·

Published

2022-03-30

·

Updated

2022-04-05

·

CVE-2021-46010

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink A3100R version 5.9c.4577
Description The issue concerns the use of insufficiently random values via the web configuration, making the SESSION ID predictable. This predictability allows an attacker to hijack a valid session and conduct further malicious operations.
Recommendations For Totolink A3100R version 5.9c.4577, consider restricting access to the web configuration until a patch is available to minimize the risk of session hijacking. As a temporary workaround, avoid using the predictable SESSION ID in the affected web configuration endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46010

Affected Products

Totolink A3100R