cbcvebase.
CVE-2018-13312
published 2018-11-26

CVE-2018-13312: Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.

Affected

1 ranges
VendorProductVersion rangeFixed in
totolinka3002ru_firmware