CVE-2024-35395: High severity TOTOLINK CP900L vulnerability
TOTOLINK CP900L v4.1.5cu.798B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35395?
CVE-2024-35395 is considered a high severity vulnerability due to the presence of a hardcoded password that allows unauthorized root access.
How do I fix CVE-2024-35395?
To mitigate CVE-2024-35395, update the firmware of your TOTOLINK CP900L device to a version that does not contain the hardcoded password.
Which versions of the TOTOLINK CP900L are affected by CVE-2024-35395?
CVE-2024-35395 affects TOTOLINK CP900L firmware version 4.1.5cu.798_B20221228.
What type of vulnerability is CVE-2024-35395?
CVE-2024-35395 is classified as a hardcoded password vulnerability, which poses risks of unauthorized access.
Can exploited CVE-2024-35395 lead to other attacks?
Yes, once attackers gain root access through CVE-2024-35395, they can potentially launch further attacks or compromise the entire network.