Cross-site Scripting in TOTOLINK A3002RU Affects User Password Security
CVE-2018-13309
6.1MEDIUM
What is CVE-2018-13309?
The TOTOLINK A3002RU version 1.0.8 is susceptible to a Cross-site Scripting (XSS) vulnerability in the password.htm file. This flaw allows attackers to inject and execute arbitrary JavaScript code, potentially compromising user credentials and enabling further exploitation of the affected system.