CVE-2024-7155
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-7155 is a newly disclosed vulnerability affecting the TOTOLINK A3300R with software version 17.0.0cu.557_B20221024. This issue lies within the unknown functionality of the file /etc/shadow.sample, which results in the use of a hard-coded password. An attacker can exploit this vulnerability on the local host, but the complexity of the attack is relatively high. The exploitation process is reportedly difficult, but the details have been made public, increasing the risk of potential attacks. The vulnerability has been given the identifier VDB-272569, and efforts to contact the vendor for a response have been unsuccessful.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK