Hardcoded Root Password Vulnerability in TOTOLINK CA300-PoE Devices
CVE-2023-24149

9.8CRITICAL

Key Information:

Vendor
Totolink
Vendor
CVE Published:
3 February 2023

Summary

The TOTOLINK CA300-PoE device version V6.2c.884 contains a significant security flaw due to a hardcoded root password stored in the vulnerable component /etc/shadow. This issue allows unauthorized users to gain elevated privileges, potentially compromising the device's security and enabling further exploitation within the network. Users are advised to implement security measures to mitigate this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.