TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 6.3epss 0.4%
probabilidade de exploração
0.4%top 63% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Produtos afetados
TOTOLINK · N600RPoCs públicas encontradas — 1
cve_referencegithub.com/b1uerry/cves/blob/main/TOTOLINK/N600R/TOTOLINK_N600R_predictable-token/poc.pynão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://github.com/b1uerry/cves/blob/main/TOTOLINK/N600R/TOTOLINK_N600R_predictable-token/poc.pyhttps://github.com/b1uerry/cves/tree/main/TOTOLINK/N600R/TOTOLINK_N600R_predictable-tokenhttps://vuldb.com/cve/CVE-2026-82555https://vuldb.com/submit/891698https://vuldb.com/vuln/397071https://vuldb.com/vuln/397071/ctihttps://www.totolink.net/