Description
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However, this JavaScript contains the current user’s password in plaintext.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154
Third Party Advisory x_refsource_misc
https://www.ise.io/casestudies/sohopelessly-broken-2-0/
Scores
CVSS v3
6.5
EPSS
0.0042
EPSS Percentile
62.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-922
Status
published
Products (1)
totolink/a3002ru_firmware
1.0.8
Published
Feb 24, 2020
Tracked Since
Feb 18, 2026