Hardcoded Root Password Vulnerability in TOTOLINK CA300-PoE Devices
CVE-2023-24149
9.8CRITICAL
Summary
The TOTOLINK CA300-PoE device version V6.2c.884 contains a significant security flaw due to a hardcoded root password stored in the vulnerable component /etc/shadow. This issue allows unauthorized users to gain elevated privileges, potentially compromising the device's security and enabling further exploitation within the network. Users are advised to implement security measures to mitigate this vulnerability.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved