CVE-2021-46009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/03/2022
Last modified:
05/04/2022

Description

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:totolink:a3100r_firmware:5.9c.4577:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:*