Hard-Coded Password Vulnerability in TCL LinkHub Mesh Wi-Fi Devices
CVE-2022-22144
7.5HIGH
What is CVE-2022-22144?
A hard-coded password vulnerability exists in the 'libcommonprod.so' component of TCL LinkHub Mesh Wi-Fi devices, specifically in the 'prod_change_root_passwd' function. This vulnerability is triggered automatically during system startup, where it exposes a known root password without any action required from an attacker. This can lead to unauthorized access, making it crucial for users to address this susceptibility to secure their network.
Affected Version(s)
LinkHub Mesh Wifi MS1G_00_01.00_14
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved