CVE-2024-24324

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 30, 2024
Updated: Feb 1, 2024
CWE ID 798

Summary

CVE-2024-24324: A critical vulnerability was identified in the TOTOLINK A8000RU v7.1cu.643_B20200521 firmware. This issue stems from a hardcoded root password being stored in the /etc/shadow file, posing a significant risk for unauthorized access. Hackers can exploit this weakness to gain administrative control over affected devices. Users are strongly advised to update their firmware as soon as a patch becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share