CVE-2022-36612: High severity totolink a950rg vulnerability
Published Aug 28, 2022
·Updated
TOTOLINK A950RG V4.1.2cu.5204B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Affected Software
2 affected components
TOTOLINK A950rg Firmware=4.1.2cu.5204_b20210112
TOTOLINK A950RG
Event History
Aug 28, 2022
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36612?
CVE-2022-36612 refers to a vulnerability found in TOTOLINK A950RG V4.1.2cu.5204_B20210112 firmware, which contains a hardcoded password for the root at /etc/shadow.sample.
2
How severe is CVE-2022-36612?
CVE-2022-36612 has a severity value of 7.8, which is considered high.
3
What is the affected software and version of CVE-2022-36612?
TOTOLINK A950RG V4.1.2cu.5204_B20210112 firmware is affected by CVE-2022-36612.
4
How can I fix CVE-2022-36612?
To fix CVE-2022-36612, it is recommended to update the firmware of TOTOLINK A950RG to a version that does not contain the hardcoded password for root.
5
Is TOTOLINK A950RG vulnerable to CVE-2022-36612?
TOTOLINK A950RG is vulnerable to CVE-2022-36612 if it is running the affected firmware version 4.1.2cu.5204_B20210112.