CVE-2024-36782

TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:cp300_firmware:2.0.4-b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:cp300:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-06-03 21:15

Updated : 2025-05-30 16:50


NVD link : CVE-2024-36782

Mitre link : CVE-2024-36782

CVE.ORG link : CVE-2024-36782


JSON object : View

Products Affected

totolink

  • cp300_firmware
  • cp300
CWE
CWE-798

Use of Hard-coded Credentials