ID

VAR-201610-0729


TITLE

Shenzhen Shengshi Zhongtang Technology Co., Ltd. TOTOLink router has a design defect vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-05707

DESCRIPTION

The TOTOLink router is a wireless broadband router from TOTOLINK. There are design flaws in the TOTOLink router of Shenzhen Shengshi Zhongtang Technology Co., Ltd. Allows an attacker to exploit the vulnerability login system to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2016-05707

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05707

AFFECTED PRODUCTS

vendor:shengshi zhongtangmodel:totolink routerscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-05707

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-05707
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-05707
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-05707

EXTERNAL IDS

db:WOOYUNid:WOOYUN-2016-0229282

Trust: 0.6

db:CNVDid:CNVD-2016-05707

Trust: 0.6

sources: CNVD: CNVD-2016-05707

REFERENCES

url:http://www.wooyun.org/bugs/wooyun-2016-0229282

Trust: 0.6

sources: CNVD: CNVD-2016-05707

SOURCES

db:CNVDid:CNVD-2016-05707

LAST UPDATE DATE

2022-05-17T01:47:55.257000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05707date:2016-08-22T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05707date:2016-10-17T00:00:00