CVE-2015-9550
published 2020-11-24CVE-2015-9550: An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.54%
72.0th percentile
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web management interface on the WAN interface.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | a850r-v1_firmware | < 1.0.1-b20150707.1612 | 1.0.1-b20150707.1612 |
| totolink | f1-v2_firmware | < 2.1.1-b20150708.1646 | 2.1.1-b20150708.1646 |
| totolink | f2-v1_firmware | < 2.1.0-b20150320.1611 | 2.1.0-b20150320.1611 |
| totolink | n150rt-v2_firmware | < 2.1.1-b20150708.1548 | 2.1.1-b20150708.1548 |
| totolink | n151rt-v2_firmware | < 1.1-b20150708.1559 | 1.1-b20150708.1559 |
| totolink | n300rh-v2_firmware | < 2.0.1-b20150708.1625 | 2.0.1-b20150708.1625 |
| totolink | n300rh-v3_firmware | < 3.0.0-b20150331.0858 | 3.0.0-b20150331.0858 |
| totolink | n300rt-v2_firmware | < 2.1.1-b20150708.1613 | 2.1.1-b20150708.1613 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-24
Published