Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Admin Password returned in password.htm
Vulnerability Description
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However, this JavaScript contains the current user’s password in plaintext.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TotoLink A3002RU 安全漏洞
Vulnerability Description
TotoLink A3002RU是中国台湾吉翁电子(TotoLink)公司的一款无线路由器产品。 使用1.0.8版本固件的TotoLink A3002RU中存在安全漏洞,该漏洞源于password.htm页面中使用的脚本包含有当前用户的明文密码。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
CVSS Information
N/A
Vulnerability Type
N/A