CVE-2022-35491: Critical severity TOTOLINK A3002ru Firmware vulnerability
Published Aug 9, 2022
·Updated
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=3.0.0-b20220304.1804
TOTOLINK A3002RU
Event History
Aug 9, 2022
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35491?
The severity of CVE-2022-35491 is critical with a CVSS score of 9.8.
2
Is TOTOLINK A3002RU V3.0.0-B20220304.1804 affected by CVE-2022-35491?
Yes, TOTOLINK A3002RU V3.0.0-B20220304.1804 is affected by CVE-2022-35491.
3
What is the vulnerability description of CVE-2022-35491?
CVE-2022-35491 is a vulnerability in TOTOLINK A3002RU V3.0.0-B20220304.1804 where a hardcoded password for root is found in /etc/shadow.sample.
4
How can I fix CVE-2022-35491?
To fix CVE-2022-35491, it is recommended to update to a patched version of TOTOLINK A3002RU firmware.
5
Where can I find more information about CVE-2022-35491?
You can find more information about CVE-2022-35491 at the following reference link: [GitHub](https://github.com/1337536723/iot/blob/main/totolink/A3002RU.md)