Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9577

Опубликовано: 28 авг. 2025
Источник: nvd
CVSS3: 2.5
CVSS3: 7
CVSS2: 1
EPSS Низкий

Описание

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:x2000r_firmware:2.0.0-b20230727.1043.web:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x2000r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00016
Низкий

2.5 Low

CVSS3

7 High

CVSS3

1 Low

CVSS2

Дефекты

CWE-1392
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 2.5
github
5 месяцев назад

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited.

CVSS3: 2.5
fstec
5 месяцев назад

Уязвимость компонента Administrative Interface файла /etc/shadow.sample микропрограммного обеспечения маршрутизаторов Totolink X2000R, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 3%
0.00016
Низкий

2.5 Low

CVSS3

7 High

CVSS3

1 Low

CVSS2

Дефекты

CWE-1392
NVD-CWE-noinfo