Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqqv-6f9q-x66q

Опубликовано: 30 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.4
CVSS3: 8.8

Описание

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 32%
0.00123
Низкий

7.4 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
nvd
7 месяцев назад

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
fstec
8 месяцев назад

Уязвимость функции Form_Login() микропрограммного обеспечения маршрутизаторов Totolink T6, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 32%
0.00123
Низкий

7.4 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-287