CVE-2018-13317
totolink a3002ru Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2018-13317 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 15, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
a3002ruBrowse totolink / a3002ru | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMTOTOLINK A3002RU 1.0.8 - Information DisclosureCVSS 6.1
TOTOLINK A3002RU firmware version 1.0.8 contains a vulnerability in which an unauthenticated attacker can obtain the plaintext admin password by making a GET request for `password.htm`. This allows remote attackers to gain administrative access without credentials.
Impact
Unauthenticated attackers can obtain the plaintext administrator password without any authentication, leading to complete device compromise.
Remediation
Update to the latest firmware version that addresses this vulnerability.
Source: ProjectDiscovery