CVE-2024-31810: Critical severity totolink ex200 vulnerability
Published May 14, 2024
·Updated
TOTOLINK EX200 V4.0.3c.7646B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Affected Software
1 affected component
totolink EX200
Event History
May 13, 2024
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
Description
May 14, 2024
Data Sourced
via NVD·03:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31810?
CVE-2024-31810 is considered a high severity vulnerability due to the presence of a hardcoded password for the root user.
2
How do I fix CVE-2024-31810?
To mitigate CVE-2024-31810, update the firmware of the TOTOLINK EX200 device to the latest version that removes the hardcoded password.
3
What impact does CVE-2024-31810 have on my device?
CVE-2024-31810 allows unauthorized access to the root account, potentially compromising the security and functionality of the TOTOLINK EX200 device.
4
Is CVE-2024-31810 exploitative?
Yes, CVE-2024-31810 can be exploited by attackers to gain control over affected TOTOLINK EX200 devices.
5
Are all versions of TOTOLINK EX200 affected by CVE-2024-31810?
The vulnerability CVE-2024-31810 affects TOTOLINK EX200 versions V4.0.3c.7646_B20201211 and potentially earlier versions.