CVE-2024-7332: TOTOLINK CP450 Telnet Service product.ini hard-coded password
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747B20191224. It has been classified as critical. This affects an unknown part of the file /webcste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7332?
CVE-2024-7332 has been classified as critical.
Which component is affected by CVE-2024-7332?
CVE-2024-7332 affects the Telnet Service component of the TOTOLINK CP450 firmware.
What type of vulnerability is described in CVE-2024-7332?
CVE-2024-7332 involves the use of a hard-coded password due to manipulation of an unspecified file.
How do I mitigate CVE-2024-7332?
To mitigate CVE-2024-7332, you should update the TOTOLINK CP450 firmware to a version without this vulnerability.
What is the affected version of the TOTOLINK CP450 firmware for CVE-2024-7332?
The affected version of the TOTOLINK CP450 firmware for CVE-2024-7332 is 4.1.0cu.747_B20191224.