CVE-2024-7155

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Jul 28, 2024
Updated: Aug 8, 2024
CWE ID 798
CWE ID 259

Summary

CVE-2024-7155 is a newly disclosed vulnerability affecting the TOTOLINK A3300R with software version 17.0.0cu.557_B20221024. This issue lies within the unknown functionality of the file /etc/shadow.sample, which results in the use of a hard-coded password. An attacker can exploit this vulnerability on the local host, but the complexity of the attack is relatively high. The exploitation process is reportedly difficult, but the details have been made public, increasing the risk of potential attacks. The vulnerability has been given the identifier VDB-272569, and efforts to contact the vendor for a response have been unsuccessful.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share