TOTOLINK A3600R Vulnerability: Hard-coded Password Exposed
CVE-2024-7159
Key Information:
Badges
What is CVE-2024-7159?
A significant vulnerability has been identified in the TOTOLINK A3600R model, specifically in the Telnet Service component. This issue arises from the use of a hard-coded password within the file located at /web_cste/cgi-bin/product.ini. The existence of this hard-coded credential poses a severe security risk, as it allows unauthorized access to the device. Public disclosure of the exploit has raised concerns, particularly given that the vendor has not provided a response to the initial notification regarding this vulnerability. Organizations using affected versions are advised to assess their risk and consider mitigation strategies to safeguard their networks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
A3600R 4.1.2cu.5182_B20201102
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
