CVE-2018-13313 Information

Description

In TOTOLINK A3002RU 1.0.8 the router provides a page that allows the user to change their account name and password. This page password.htm contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However this JavaScript contains the current user’s password in plaintext.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Reference

https://blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154 https://www.ise.io/casestudies/sohopelessly-broken-2-0/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: