PT-2022-6265 · Totolink · Totolink N200Re V5
Wenyi Li
·
Published
2022-12-23
·
Updated
2025-03-26
·
CVE-2022-48113
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TOTOLINK N200RE V5 versions prior to the fixed version
Description
The issue is related to the use of hardcoded credentials in the Telnet service of the TOTOLINK N200RE V5 router firmware, which allows unauthorized access to sensitive information. An attacker can exploit this by sending a specially crafted POST request to gain access to the telnet service and login as root using the hardcoded credentials.
Recommendations
For TOTOLINK N200RE V5 versions prior to the fixed version, consider disabling the telnet service until a patch is available to prevent exploitation.
As a temporary workaround, restrict access to the router's administrative interface to minimize the risk of unauthorized access.
Avoid using the hardcoded credentials in the telnet service until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink N200Re V5