CVE-2022-36610: High severity totolink a720r firmware vulnerability
TOTOLINK A720R V4.1.5cu.532B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36610?
CVE-2022-36610 is a vulnerability found in TOTOLINK A720R V4.1.5cu.532_B20210610 firmware that contains a hardcoded password for root at /etc/shadow.sample.
What is the severity of CVE-2022-36610?
The severity of CVE-2022-36610 is high, with a CVSS score of 7.8.
How does CVE-2022-36610 affect the TOTOLINK A720R firmware?
CVE-2022-36610 affects the TOTOLINK A720R firmware version 4.1.5cu.532_B20210610 by exposing a hardcoded password for root at /etc/shadow.sample.
Is TOTOLINK A720R V4.1.5cu.532_B20210610 vulnerable to CVE-2022-36610?
Yes, TOTOLINK A720R V4.1.5cu.532_B20210610 is vulnerable to CVE-2022-36610 due to the presence of a hardcoded password for root.
How can I fix CVE-2022-36610?
To fix CVE-2022-36610, users should update their TOTOLINK A720R firmware to a version that does not contain the hardcoded password vulnerability.