CVE-2024-36782

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
03/06/2024
Last modified:
30/05/2025

Description

TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:totolink:cp300_firmware:2.0.4-b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:cp300:2.0:*:*:*:*:*:*:*