CVE-2024-34211: High severity totolink cp450 firmware vulnerability
Published May 14, 2024
·Updated
TOTOLINK CP450 v4.1.0cu.747B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
Affected Software
1 affected component
TOTOLINK CP450
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:38 PM
Data Sourced
via NVD·03:38 PM
DescriptionSeverityWeakness
Aug 15, 2024
Data Sourced
via MITRE·06:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34211?
CVE-2024-34211 is considered a critical severity vulnerability due to the hardcoded password allowing root access.
2
How do I fix CVE-2024-34211?
To fix CVE-2024-34211, update the TOTOLINK CP450 firmware to the latest version that removes the hardcoded password.
3
What systems are affected by CVE-2024-34211?
CVE-2024-34211 affects TOTOLINK CP450 devices running version 4.1.0cu.747_B20191224.
4
What type of vulnerability is CVE-2024-34211?
CVE-2024-34211 is a hardcoded password vulnerability that allows unauthorized root access.
5
Who discovered CVE-2024-34211?
CVE-2024-34211 was identified by security researchers focusing on IoT vulnerabilities.