CVE-2022-36615: High severity totolink a3000ru firmware vulnerability
TOTOLINK A3000RU V4.1.2cu.5185B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36615?
CVE-2022-36615 is a vulnerability discovered in TOTOLINK A3000RU V4.1.2cu.5185_B20201128 firmware that contains a hardcoded password for root.
What is the severity of CVE-2022-36615?
CVE-2022-36615 has a severity rating of 7.8, which is considered high.
How does CVE-2022-36615 affect TOTOLINK A3000RU firmware?
CVE-2022-36615 affects TOTOLINK A3000RU firmware version 4.1.2cu.5185_B20201128 by including a hardcoded password for root in the /etc/shadow.sample file.
Is TOTOLINK A3000RU V4.1.2cu.5185_B20201128 vulnerable to CVE-2022-36615?
Yes, TOTOLINK A3000RU V4.1.2cu.5185_B20201128 is vulnerable to CVE-2022-36615 due to the hardcoded password for root.
How can I mitigate the vulnerability in TOTOLINK A3000RU V4.1.2cu.5185_B20201128?
To mitigate the vulnerability in TOTOLINK A3000RU V4.1.2cu.5185_B20201128, it is recommended to update the firmware to a version that does not contain the hardcoded password for root.