Medium severity6.1NVD Advisory· Published Nov 26, 2018· Updated Jun 17, 2026
CVE-2018-13317
CVE-2018-13317
Description
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
Affected products
2- cpe:2.3:o:totolink:a3002ru_firmware:1.0.8:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.