High severity8.8NVD Advisory· Published Mar 30, 2022· Updated Jul 9, 2026
CVE-2021-46010
CVE-2021-46010
Description
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
Affected products
3- cpe:2.3:o:totolink:a3100r_firmware:5.9c.4577:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- hackmd.io/Ynwm8NnQSiK0xm7QKuNtegnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.