Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43m2-5vcp-3fpm

Опубликовано: 27 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.5
CVSS3: 7.3

Описание

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 38%
0.00168
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
fstec
6 месяцев назад

Уязвимость функции formAuthLogin файла /formLoginAuth.htm микропрограммного обеспечения маршрутизатора TOTOLINK T10, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 38%
0.00168
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-287