Unauthorized Telnet Access in TOTOLINK EX1200T Router
CVE-2021-42892

4.3MEDIUM

Key Information:

Vendor
Totolink
Vendor
CVE Published:
3 June 2022

Summary

The TOTOLINK EX1200T router is vulnerable due to the existence of default username and password credentials in its firmware. An attacker can exploit this vulnerability to initiate a telnet session without any prior authentication. This opens the door for potential unauthorized access to the device, allowing malicious actors to manipulate or control the router settings, jeopardizing network security.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.