KEVIntel
9.8
CVSS
Critical

CVE-2018-13315

PUBLISHED

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an...

Exploited in the wild Remote Low complexity No user interaction
Vendor
TOTOLINK
Product
A3002RU
Published
Nov 26, 2018
EPSS

Description

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.

edge

CVSS scores

CVSS v3.0 9.8 Critical

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 5.0

AV:N/AC:L/Au:N/C:N/I:P/A:N

Exploitation status

Exploited in the wild

Recorded 2025-04-26 00:00:00 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 26, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel