CVE-2024-7170: TOTOLINK A3000RU product.ini hard-coded password
A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /webcste/cgi-bin/product.ini. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272591. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7170?
CVE-2024-7170 has been rated as problematic.
What is the impact of CVE-2024-7170 on affected devices?
The vulnerability in CVE-2024-7170 leads to the use of a hard-coded password.
How do I fix CVE-2024-7170?
To fix CVE-2024-7170, update the TOTOLINK A3000RU firmware to a version that addresses this vulnerability.
Which devices are affected by CVE-2024-7170?
CVE-2024-7170 affects the TOTOLINK A3000RU with firmware version 5.9c.5185.
Is there a known exploit for CVE-2024-7170?
Yes, the exploit for CVE-2024-7170 has been disclosed to the public.