PT-2023-9015 · Totolink · Totolink N200Re

Lin7Lic

·

Publicado

2023-05-18

·

Atualizado

2024-05-17

·

CVE-2023-2790

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK N200RE version 9.3.5u.6255 B20211224
Description A problematic vulnerability has been found in the Telnet Service component of the TOTOLINK N200RE, affecting an unknown function of the file /squashfs-root/etc ro/custom.conf. The manipulation leads to exposure of passwords in the configuration file. This issue can be exploited locally. The vulnerability is related to the use of an unstable cryptographic algorithm in configuration files, which may allow an attacker to gain unauthorized access to protected information.
Recommendations For TOTOLINK N200RE version 9.3.5u.6255 B20211224, consider disabling the Telnet Service or restricting access to the /squashfs-root/etc ro/custom.conf file as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-03019
CVE-2023-2790

Produtos afetados

Totolink N200Re