Skip to content
COOEY

EXPOSURES › CVE-2021-46009

CVE-2021-46009

CRITICAL
DETAIL
SourceNVD · cve Published2022-03-30 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-46009 ↗
SHAME 35/100

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.