PT-2022-23509 · Totolink · Totolink A3000Ru

Whiter6666

·

Published

2022-08-28

·

Updated

2022-09-01

·

CVE-2022-36615

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3000RU version 4.1.2cu.5185 B20201128
Description A hardcoded password for the root user was found in the /etc/shadow.sample file. This issue allows unauthorized access to the device.
Recommendations For TOTOLINK A3000RU version 4.1.2cu.5185 B20201128, consider changing the root password as soon as possible to prevent unauthorized access. As a temporary workaround, restrict access to the device until a patch is available.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-36615

Affected Products

Totolink A3000Ru