CVE-2021-46008
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
30/03/2022
Last modified:
05/04/2022
Description
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
7.90
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:totolink:a3100r_firmware:5.9c.4577:*:*:*:*:*:*:* | ||
| cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



