Security Advisory

CVE-2018-13307

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-11-27 21:00:00
Last updated 2024-08-05 09:00:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.