PT-2022-23509 · Totolink · Totolink A3000Ru

·

CVE-2022-36615

·

Published

2022-08-28

·

Updated

2022-09-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3000RU version 4.1.2cu.5185 B20201128
Description A hardcoded password for the root user was found in the /etc/shadow.sample file. This issue allows unauthorized access to the device.
Recommendations For TOTOLINK A3000RU version 4.1.2cu.5185 B20201128, consider changing the root password as soon as possible to prevent unauthorized access. As a temporary workaround, restrict access to the device until a patch is available.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36615

Affected Products

Totolink A3000Ru