In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Link | Tags |
---|---|
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/171/ids/36.html | product |
http://a7000rfirmware.com | broken link |
https://gist.github.com/lin-3-start/5b20f6fbe3aa0c3fc75f320cd589182a | third party advisory |