CVE-2021-46008: High severity TOTOLINK A3100r Firmware vulnerability

Published Mar 30, 2022
·
Updated

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.

Affected Software

4 affected components
TOTOLINK A3100r Firmware=5.9c.4577
TOTOLINK A3100R
All of the following
TOTOLINK A3100r Firmware=5.9c.4577
TOTOLINK A3100R

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade totolink a3100r to a version that resolves this vulnerability.

    Fixed in V5.9c.4577
  2. Configuration

    Disable Telnet on the router, since having Telnet enabled allows an attacker connected to Wi‑Fi to telnet into the device with a root shell.

    Telnet service enabled = false
  3. Compensating control

    Restrict access to the router’s Telnet interface from the network (e.g., block Telnet at firewall/ACL) to prevent Telnet root-shell access from connected clients.

Event History

Mar 30, 2022
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID of this totolink a3100r firmware vulnerability?

The vulnerability ID is CVE-2021-46008.

2

What is the severity level of CVE-2021-46008?

The severity level of CVE-2021-46008 is high, with a score of 8.8.

3

How can the hard-coded telnet password be discovered in totolink a3100r V5.9c.4577?

The hard-coded telnet password can be discovered from the official released firmware of totolink a3100r V5.9c.4577.

4

What can an attacker do if they discover the hard-coded telnet password in totolink a3100r V5.9c.4577?

If an attacker has connected to the Wi-Fi, they can easily telnet into the target with root shell if the telnet function is turned on.

5

How can the totolink a3100r firmware vulnerability be fixed?

Updating to a patched version of the totolink a3100r firmware can fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203