CVE-2022-36614: High severity totolink a860r firmware vulnerability
Published Aug 28, 2022
·Updated
TOTOLINK A860R V4.1.2cu.5182B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Affected Software
2 affected components
TOTOLINK A860r Firmware=4.1.2cu.5182_b20201027
TOTOLINK A860R
Event History
Aug 28, 2022
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36614?
CVE-2022-36614 is classified as a high severity vulnerability due to the presence of a hardcoded root password.
2
What does CVE-2022-36614 affect?
CVE-2022-36614 affects TOTOLINK A860R firmware version 4.1.2cu.5182_B20201027.
3
How do I fix CVE-2022-36614?
To fix CVE-2022-36614, update the firmware of the TOTOLINK A860R to a version that removes the hardcoded password.
4
What are the consequences of CVE-2022-36614?
CVE-2022-36614 can lead to unauthorized access to the device due to the static root password, compromising device security.
5
Is there a workaround for CVE-2022-36614?
There are no effective workarounds for CVE-2022-36614 other than applying the necessary firmware update to mitigate the risk.