Headline
CVE-2021-46009: CVE-2021-46009 - HackMD
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
HackMD
- Create new note
- Create a note from template
- Options
- Versions and GitHub Sync
- Transfer ownership
- Delete this note
- Template
- Save as template
- Insert from template
- Export
- Dropbox
- Google Drive
- Gist
- Import
- Dropbox
- Google Drive
- Gist
- Clipboard
- Download
- Markdown
- HTML
- Raw HTML
- ODF (Beta)
Sharing
View mode
- Edit mode
- View mode
- Book mode
- Slide mode
Note Permission
Read
- Owners
- Signed-in users
- Everyone
Write
- Owners
- Signed-in users
- Everyone
More (Comment, Invitee)