cbcvebase.
CVE-2018-13308
published 2018-11-26

CVE-2018-13308: Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.

Affected

1 ranges
VendorProductVersion rangeFixed in
totolinka3002ru_firmware