CVE-2024-7332
A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 20.74%
- CWE
- CWE-259
- Published
- 2024-08-01
- Last modified
- 2026-03-13
Affected products
- TOTOLINK CP450
Weakness type
Related vulnerabilities
- CVE-2023-5222 — Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
- CVE-2012-5862 — Sinapsi eSolar Hard-Coded Password
- CVE-2023-2645 — USR USR-G806 Web Management Page hard-coded password
- CVE-2022-45444 — CVE-2022-45444
- CVE-2014-2363 — Morpho Itemiser 3 Hard-Coded Credential
- CVE-2025-8730 — Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
- CVE-2025-11126 — Apeman ID71 system.ini hard-coded credentials
- CVE-2024-32741 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa