First published: Sun Aug 28 2022(Updated: )
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A860R Firmware | =4.1.2cu.5182_b20201027 | |
Totolink A860R Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36614 is classified as a high severity vulnerability due to the presence of a hardcoded root password.
CVE-2022-36614 affects TOTOLINK A860R firmware version 4.1.2cu.5182_B20201027.
To fix CVE-2022-36614, update the firmware of the TOTOLINK A860R to a version that removes the hardcoded password.
CVE-2022-36614 can lead to unauthorized access to the device due to the static root password, compromising device security.
There are no effective workarounds for CVE-2022-36614 other than applying the necessary firmware update to mitigate the risk.