TOTOLINK A3002RU firmware version 1.0.8 contains a vulnerability in which an unauthenticated attacker can obtain the plaintext admin password by making a GET request for `password.htm`. This allows remote attackers to gain administrative access without credentials.
id: CVE-2018-13317
info:
name: TOTOLINK A3002RU 1.0.8 - Information Disclosure
author: ritikcha
...