CVE-2021-46009EPSS p95.9%

CVE-2021-46009CVE-2021-46009

totolink / a3100r_firmware

Description

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.34% probability of exploitation · percentile 95.9% · 2026-08-18T12:04:07Z
Last modified2026-07-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.