PT-2022-4464 · Totolink · Totolink A810R
Whiter6666
·
Published
2022-08-28
·
Updated
2022-09-01
·
CVE-2022-36616
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A810R versions V4.1.2cu.5182 B20201026 through V5.9c.4050 B20190424
Description
The issue is related to a hardcoded password for the root user at
/etc/shadow.sample. This could allow a remote attacker to elevate their privileges. The vulnerability is associated with the use of predefined credentials in the TOTOLINK A810R router's firmware.Recommendations
For versions V4.1.2cu.5182 B20201026 and V5.9c.4050 B20190424, consider changing the hardcoded password for the root user at
/etc/shadow.sample to a unique and secure password.
As a temporary workaround, restrict access to the /etc/shadow.sample file until a patch is available.
Avoid using the default credentials for the root user in the affected firmware versions until the issue is resolved.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink A810R