CVE-2022-40111: Critical severity TOTOLINK A3002R Firmware vulnerability
Published Sep 6, 2022
·Updated
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
Affected Software
4 affected components
TOTOLINK A3002R Firmware=1.1.1-b20200824.0128
TOTOLINK A3002R
All of the following
TOTOLINK A3002R Firmware=1.1.1-b20200824.0128
TOTOLINK A3002R
Event History
Sep 6, 2022
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this TOTOLINK A3002R firmware issue?
The vulnerability ID for this issue is CVE-2022-40111.
2
What is the severity of CVE-2022-40111?
CVE-2022-40111 has a severity rating of 9.8 (Critical).
3
What is the affected software version for CVE-2022-40111?
The affected software version for CVE-2022-40111 is Totolink A3002r Firmware 1.1.1-b20200824.0128.
4
What is the CWE ID associated with CVE-2022-40111?
The CWE ID associated with CVE-2022-40111 is CWE-798.
5
Is TOTOLINK A3002R firmware version vulnerable to CVE-2022-40111?
No, TOTOLINK A3002R firmware version is not vulnerable to CVE-2022-40111.