CVE-2023-24147: High severity totolink ca300-poe vulnerability
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24147?
The severity of CVE-2023-24147 is high with a CVSS score of 7.5.
How does CVE-2023-24147 impact TOTOLINK CA300-PoE V6.2c.884?
CVE-2023-24147 impacts TOTOLINK CA300-PoE V6.2c.884 by exposing a hard code password for the telnet service, which can be exploited by attackers.
Where is the hard code password for the telnet service stored in TOTOLINK CA300-PoE V6.2c.884?
The hard code password for the telnet service in TOTOLINK CA300-PoE V6.2c.884 is stored in the component /etc/config/product.ini.
Is TOTOLINK CA300-PoE V6.2c.884 the only affected software?
No, TOTOLINK CA300-PoE V6.2c.884 is not the only affected software. Other versions or models may also be vulnerable.
How can I fix CVE-2023-24147 in TOTOLINK CA300-PoE V6.2c.884?
To fix CVE-2023-24147 in TOTOLINK CA300-PoE V6.2c.884, it is recommended to update the firmware to a patched version provided by the vendor.