RULE(RULE ID:337795)

Rule General Information
Release Date: 2024-01-23
Rule Name: Totolink Login Authentication Bypass Vulnerability (CVE-2021-42887 CVE-2022-48066)
Severity:
CVE ID:
Rule Protection Details
Description: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference: https://github.com/p1Kk/vuln/blob/main/totolink_ex1200t_login_bypass.md
https://cxsecurity.com/cveshow/CVE-2021-42887/
Solutions
Refer to the announcement or patch by the vendor: http://totolink.net/