PT-2026-56965 · Totolink · Ac1200T10+6
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A3000RU versions prior to 20260906
TOTOLINK A3100R versions prior to 20260906
TOTOLINK A950RG versions prior to 20260906
TOTOLINK AC1200T10 versions prior to 20260906
TOTOLINK CP450 versions prior to 20260906
TOTOLINK CS185R T10 versions prior to 20260906
TOTOLINK EX200 versions prior to 20260906
Description
A least privilege violation exists in the Web Interface component due to an issue within the
/etc/boa/boa.conf file. This flaw allows a remote attacker to manipulate the system, although the attack complexity is high and exploitation is considered difficult.Recommendations
Update TOTOLINK A3000RU to a version released after 20260906.
Update TOTOLINK A3100R to a version released after 20260906.
Update TOTOLINK A950RG to a version released after 20260906.
Update TOTOLINK AC1200T10 to a version released after 20260906.
Update TOTOLINK CP450 to a version released after 20260906.
Update TOTOLINK CS185R T10 to a version released after 20260906.
Update TOTOLINK EX200 to a version released after 20260906.
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A3000Ru
A3100R
A950Rg
Ac1200T10
Cp450
Cs185R T10
Ex200