PoC Index

CVE-2018-13307

HIGH 10.0EPSS 3.2%

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
3.19% chance of exploitation in the next 30 days, 87th percentile
Published
2018-11-27
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related