Record summary

CVE-2018-13317 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 15, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMTOTOLINK A3002RU 1.0.8 - Information DisclosureCVSS 6.1

TOTOLINK A3002RU firmware version 1.0.8 contains a vulnerability in which an unauthenticated attacker can obtain the plaintext admin password by making a GET request for `password.htm`. This allows remote attackers to gain administrative access without credentials.

Impact

Unauthenticated attackers can obtain the plaintext administrator password without any authentication, leading to complete device compromise.

Remediation

Update to the latest firmware version that addresses this vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2018totolinkpasswordexposurevkev
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:totolink:a3002ru_firmware:1.0.8:*:*:*:*:*:*:*
FOFA: title="totolink"

Source: ProjectDiscovery

References

2