PT-2022-24110 · Totolink · Totolink A860R

Published

2022-09-06

·

Updated

2022-09-08

·

CVE-2022-37841

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK A860R version 4.1.2cu.5182 B20201027
Description The issue concerns a hard-coded password for the root user, located in the /etc/shadow.sample file.
Recommendations For TOTOLINK A860R version 4.1.2cu.5182 B20201027, consider changing the hard-coded password for the root user in the /etc/shadow.sample file to prevent unauthorized access. As a temporary workaround, restrict root access to the device until a patch is available.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-37841

Affected Products

Totolink A860R