CVE-2018-13315
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 1.6%
from disclosure to weapon
Published on NVDNov 26
VulnCheck+1897d
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
yesVulnCheck
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
Affected products
n/a · n/a