First published: Fri Feb 03 2023(Updated: )
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Ca300-poe Firmware | =6.2c.884 | |
TOTOLINK CA300-PoE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24149 has been classified as a high-severity vulnerability due to the hardcoded root password.
To fix CVE-2023-24149, update the firmware of the TOTOLINK CA300-PoE device to a version that does not contain the hardcoded password.
CVE-2023-24149 affects the TOTOLINK CA300-PoE device running firmware version 6.2c.884.
The potential risks of CVE-2023-24149 include unauthorized access to the device and compromise of the network.
The vendor, TOTOLINK, is responsible for providing a patch or firmware update to address CVE-2023-24149.