CVE-2023-24155: Critical severity totolink t8 firmware vulnerability
Published Feb 3, 2023
·Updated
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /webcste/cgi-bin/product.ini.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24155?
CVE-2023-24155 is considered a high severity vulnerability due to its hardcoded password for the telnet service.
2
How do I fix CVE-2023-24155?
To fix CVE-2023-24155, you should update the TOTOLINK T8 firmware to a version that removes the hardcoded password.
3
What is affected by CVE-2023-24155?
CVE-2023-24155 impacts TOTOLINK T8 devices running firmware version v4.1.5cu.
4
What types of attacks can exploit CVE-2023-24155?
Attackers can exploit CVE-2023-24155 to gain unauthorized access to the device through the telnet service.
5
Is my device safe if it is not running v4.1.5cu firmware regarding CVE-2023-24155?
Devices running firmware versions other than v4.1.5cu may not be vulnerable to CVE-2023-24155 depending on the presence of the hardcoded password.