Vulnerability in TOTOLINK's A3000RU 5.9c.5185due to Hard-Coded Password
CVE-2024-7170
8.8HIGH
Summary
A problematic vulnerability has been identified in the TOTOLINK A3000RU router, specifically in version 5.9c.5185, where the file /web_cste/cgi-bin/product.ini contains hard-coded passwords. This security flaw allows for unauthorized access and manipulation of configuration settings, posing a significant risk to network integrity. The vulnerability was publicly disclosed despite early vendor notification, raising concerns about timely security responses and user safety.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published