Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-13317Cross-site Scripting in A3002ru Firmware

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 50.37%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 26
Latest updateMay 14

Description

Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-pph5-pqjx-vh8h: Password disclosure in password2022-05-14
CVEList
CVE-2018-13317: Password disclosure in password2018-11-26
VulnCheck
totolink a3002ru Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2018

💥Exploits & PoCs

1
Nuclei
TOTOLINK A3002RU 1.0.8 - Information Disclosure
CVE-2018-13317 — Cross-site Scripting | cvebase