CVE-2021-46010
a3100r firmware, a3100r
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
- CVSS
- 8.8
- EPSS
- 1.21% 65.6% percentile
- CISA KEV
- Not listed
- Published
- 2022.03.31