First published: Sun Aug 28 2022(Updated: )
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A950rg Firmware | =4.1.2cu.5204_b20210112 | |
TOTOLink A950RG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36612 refers to a vulnerability found in TOTOLINK A950RG V4.1.2cu.5204_B20210112 firmware, which contains a hardcoded password for the root at /etc/shadow.sample.
CVE-2022-36612 has a severity value of 7.8, which is considered high.
TOTOLINK A950RG V4.1.2cu.5204_B20210112 firmware is affected by CVE-2022-36612.
To fix CVE-2022-36612, it is recommended to update the firmware of TOTOLINK A950RG to a version that does not contain the hardcoded password for root.
TOTOLINK A950RG is vulnerable to CVE-2022-36612 if it is running the affected firmware version 4.1.2cu.5204_B20210112.