cbcvebase.
CVE-2018-13309
published 2018-11-26

CVE-2018-13309: Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.

Affected

1 ranges
VendorProductVersion rangeFixed in
totolinka3002ru_firmware