Hardcoded Password Vulnerability in TOTOLINK A800R Router
CVE-2022-36611
7.8HIGH
Summary
The TOTOLINK A800R router version V4.1.2cu.5137_B20200730 has been identified to contain a vulnerability due to a hardcoded password for the root account, located in the /etc/shadow.sample file. This vulnerability allows unauthorized access to sensitive system configurations and poses a significant risk to the security and integrity of the network it serves. Users are advised to update to a patched version and to implement additional security measures to safeguard their devices against potential exploitation.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved