CVE-2021-46008

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/03/2022
Last modified:
05/04/2022

Description

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:totolink:a3100r_firmware:5.9c.4577:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:*