TOTOLINK A3002R
cpe:2.3:h:totolink:a3002r:*:*:*:*:*:*:*, +1 more
- V4.0.0-B20230531.1404
A vulnerability exists in the TOTOLINK A3002R router, specifically in version 4.0.0-B20230531.1404, due to insecure credentials for the telnet service and root account. This issue arises from a hard-coded shadow.sample file that can be exploited to gain unauthorized access via telnet.
Exploitation of this vulnerability allows for unauthorized access to the device's telnet service, potentially leading to further exploitation or manipulation of the device.
The vulnerability can be reproduced by accessing the device's telnet service on port 23. Once connected, the hard-coded shadow.sample file can be used to gain root access, as the file contains insecure credentials that can be exploited.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.