CVE-2021-46008 Information

Description

In totolink a3100r V5.9c.4577 the hard-coded telnet password can be discovered from official released firmware. An attacker who has connected to the Wi-Fi can easily telnet into the target with root shell if the telnet is function turned on.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

http://a3100r.com https://hackmd.io/ZkeEB-VvRiWBS53rFKG8DQ http://totolink.com

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: