peter bassill · operator
$ cve CVE-2021-46009 JSON

CVE-2021-46009

9.8
CRITICAL · CVSS 3.1 · EPSS 12.5% (pctl 96)

Patch early

EPSS 12.5% — above the 10% action threshold.

Description

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.53% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2022-03-30
Last modified2026-07-09

Affected (2)

VendorProduct
totolinka3100r
totolinka3100r firmware

References

→ the Explorer  ·  watch your stack  ·  NVD