Vulnerability in TOTOLINK's A3000RU 5.9c.5185due to Hard-Coded Password
CVE-2024-7170

8.8HIGH

Key Information:

Vendor
TOTOLINK
Vendor
CVE Published:
28 July 2024

Summary

A problematic vulnerability has been identified in the TOTOLINK A3000RU router, specifically in version 5.9c.5185, where the file /web_cste/cgi-bin/product.ini contains hard-coded passwords. This security flaw allows for unauthorized access and manipulation of configuration settings, posing a significant risk to network integrity. The vulnerability was publicly disclosed despite early vendor notification, raising concerns about timely security responses and user safety.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.