Vulnerability Description
Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | N200Re V5 Firmware | 9.3.5u.6255_b20211224 |
| Totolink | N200Re V5 | - |
Related Weaknesses (CWE)
References
- https://pastebin.com/aan5jT40PatchThird Party Advisory
- https://pastebin.com/aan5jT40PatchThird Party Advisory
FAQ
What is CVE-2022-46025?
CVE-2022-46025 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, witho...
How severe is CVE-2022-46025?
CVE-2022-46025 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-46025?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink N200Re V5 Firmware, Totolink N200Re V5.