CVE-2024-24324: Critical severity TOTOLINK A8000ru Firmware vulnerability
Published Jan 30, 2024
·Updated
TOTOLINK A8000RU v7.1cu.643B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
Affected Software
2 affected components
All of the following
TOTOLINK A8000ru Firmware=7.1cu.643_b20200521
TOTOLINK A8000RU
Event History
Jan 30, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24324?
CVE-2024-24324 has a high severity due to the presence of a hardcoded password for the root user.
2
How do I fix CVE-2024-24324?
To fix CVE-2024-24324, update the TOTOLINK A8000RU firmware to a version that does not have the hardcoded password.
3
What are the potential risks of CVE-2024-24324?
The risks of CVE-2024-24324 include unauthorized access to the router's admin interface and potential compromise of the network.
4
Which versions of software are affected by CVE-2024-24324?
CVE-2024-24324 affects TOTOLINK A8000RU firmware version 7.1cu.643_B20200521.
5
Is there a workaround for CVE-2024-24324?
Currently, there is no known workaround for CVE-2024-24324; the recommended solution is to update the firmware.