CVE-2018-13307
27.11.2018, 20:29
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.
| Vendor | Product | Version |
|---|---|---|
| totolink | a3002ru_firmware | 1.0.8 |
𝑥
= Vulnerable software versions