Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g76c-g25x-rqgp

Опубликовано: 28 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1.1
CVSS3: 2.5

Описание

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited.

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited.

EPSS

Процентиль: 5%
0.00021
Низкий

1.1 Low

CVSS4

2.5 Low

CVSS3

Дефекты

CWE-1392

Связанные уязвимости

CVSS3: 2.5
nvd
5 месяцев назад

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited.

CVSS3: 2.5
fstec
5 месяцев назад

Уязвимость компонента Administrative Interface файла /etc/shadow.sample микропрограммного обеспечения маршрутизаторов Totolink X2000R, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 5%
0.00021
Низкий

1.1 Low

CVSS4

2.5 Low

CVSS3

Дефекты

CWE-1392