In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/204/ids/36.html | product |
http://n200re.com | broken link |
https://gist.github.com/lin-3-start/e42344d5caea881e5429fdd40fad1fd8 | third party advisory |