Vulnerability Description
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | A702R Firmware | 1.0.0-b20161227.1023 |
| Totolink | A702R | - |
Related Weaknesses (CWE)
References
- https://github.com/swzhouu/CVE-2020-27368ExploitThird Party Advisory
- https://github.com/swzhouu/CVE-2020-27368ExploitThird Party Advisory
FAQ
What is CVE-2020-27368?
CVE-2020-27368 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.
How severe is CVE-2020-27368?
CVE-2020-27368 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27368?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink A702R Firmware, Totolink A702R.