github.com
https://github.com/hurricane618/my_cves/blob/master/router/totolink/A720R_default_telnet_info.md CVE-2021-35327
CRITICAL
totolink a720r_firmware Missing Authorization
Record summary
CVE-2021-35327 has a selected CVSS score of 9.8 (critical).
Description
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 16, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
a720r_firmwareBrowse totolink / a720r_firmware | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-35327