Incorrect Access Control in Totolink Product
CVE-2022-46025

9.1CRITICAL

Key Information:

Vendor
Totolink
Vendor
CVE Published:
10 January 2024

Summary

The Totolink N200RE_V5, specifically version V9.3.5u.6255_B20211224, is exposed to an Incorrect Access Control vulnerability. This flaw enables remote attackers to exploit the system, granting unauthorized access to sensitive Wi-Fi system information, including the Wi-Fi SSID and password. Such vulnerabilities pose significant risks, allowing malicious entities to infiltrate networks and potentially compromise user data and privacy. It is crucial for users and network administrators to implement security measures to protect against these unauthorized access risks.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.