CVE-2022-38823: Critical severity totolink t6 firmware vulnerability
Published Sep 16, 2022
·Updated
In TOTOLINK T6 V4.1.5cu.709B20210518, there is a hard coded password for root in /etc/shadow.sample.
Affected Software
2 affected components
TOTOLINK T6 Firmware=4.1.5cu.709_b20210518
TOTOLINK T6=3
Event History
Sep 16, 2022
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38823?
CVE-2022-38823 is classified as a high-severity vulnerability due to the presence of a hard-coded password.
2
How do I fix CVE-2022-38823?
To fix CVE-2022-38823, you should update the TOTOLINK T6 firmware to a version that removes the hard-coded password.
3
What are the implications of CVE-2022-38823?
The implications of CVE-2022-38823 include the potential for unauthorized access to the device using the hard-coded root password.
4
Which software versions are affected by CVE-2022-38823?
CVE-2022-38823 affects the TOTOLINK T6 firmware version 4.1.5cu.709_B20210518.
5
Is the TOTOLINK T6 hardware vulnerable due to CVE-2022-38823?
No, the hardware itself is not vulnerable; the vulnerability is specific to the firmware version.