CVE-2022-25008: High severity totolink ex300 v2 firmware vulnerability
Published Mar 30, 2022
·Updated
totolink EX300v2 V4.0.3c.140B20210429 and EX1200T V4.1.2cu.5230B20210706 does not contain an authentication mechanism.
Affected Software
4 affected components
TOTOLINK Ex300 V2 Firmware=4.0.3c.140_b20210429
TOTOLINK Ex300 V2
TOTOLINK EX1200T firmware=4.1.2cu.5230_b20210706
TOTOLINK EX1200T
Event History
Mar 30, 2022
CVE Published
via MITRE·10:27 PM
Data Sourced
via MITRE·10:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25008?
The severity of CVE-2022-25008 is high, with a severity value of 8.8.
2
Which devices are affected by CVE-2022-25008?
The totolink EX300_v2 with firmware version 4.0.3c.140_B20210429 and EX1200T with firmware version 4.1.2cu.5230_B20210706 are affected by CVE-2022-25008.
3
What is the vulnerability description of CVE-2022-25008?
CVE-2022-25008 is a vulnerability in totolink EX300_v2 and EX1200T devices, where it does not contain an authentication mechanism.
4
How can I fix CVE-2022-25008?
Currently, there is no available fix for CVE-2022-25008. It is recommended to contact the vendor for updates or patches.
5
Where can I find more information about CVE-2022-25008?
You can find more information about CVE-2022-25008 in the reference link: https://github.com/chibataiki/iot-vuls/blob/main/totolink/missing-authentication.md