Hardcoded Password Vulnerability in TOTOLINK A800R Router
CVE-2022-36611

7.8HIGH

Key Information:

Vendor
Totolink
Vendor
CVE Published:
29 August 2022

Summary

The TOTOLINK A800R router version V4.1.2cu.5137_B20200730 has been identified to contain a vulnerability due to a hardcoded password for the root account, located in the /etc/shadow.sample file. This vulnerability allows unauthorized access to sensitive system configurations and poses a significant risk to the security and integrity of the network it serves. Users are advised to update to a patched version and to implement additional security measures to safeguard their devices against potential exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.