Hard-Coded Password Vulnerability in TCL LinkHub Mesh Wi-Fi Devices
CVE-2022-22144

7.5HIGH

Key Information:

Vendor

Tcl

Vendor
CVE Published:
5 August 2022

What is CVE-2022-22144?

A hard-coded password vulnerability exists in the 'libcommonprod.so' component of TCL LinkHub Mesh Wi-Fi devices, specifically in the 'prod_change_root_passwd' function. This vulnerability is triggered automatically during system startup, where it exposes a known root password without any action required from an attacker. This can lead to unauthorized access, making it crucial for users to address this susceptibility to secure their network.

Affected Version(s)

LinkHub Mesh Wifi MS1G_00_01.00_14

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.