S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 25, 2024

CVE-2024-7332 Scanner

CVE-2024-7332 scanner - Hard-Coded Password vulnerability in TOTOLINK CP450

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-7332
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CP450by TOTOLINK
4.1.0cu.747_B20191224
cp450_firmwareby totolink
4.1.0cu.747_b20191224
Updated Sep 10, 2026View on NVD →
Detail

TOTOLINK CP450 is a widely used router in homes and small businesses, providing wireless networking and internet connectivity. It is designed for ease of use and quick setup, often utilized by users with limited technical knowledge. The CP450 model includes features such as guest networks and parental controls. However, it is primarily aimed at budget-conscious users who require reliable basic networking. Its firmware is periodically updated to address security and performance issues.

The TOTOLINK CP450 router has a critical security flaw due to a hard-coded password within its firmware. This vulnerability exists in version 4.1.0cu.747_B20191224 and allows attackers to gain unauthorized access to the device remotely. The flaw is located in the Telnet service, where the hard-coded password can be exploited without user interaction. This issue poses significant security risks to affected networks.

The vulnerability is found in the Telnet Service component of the TOTOLINK CP450 router, specifically within the file /web_cste/cgi-bin/product.ini. The file contains a hard-coded password, which is embedded in the firmware, providing no means for users to modify or remove it. This password can be easily extracted or exploited by remote attackers, granting them full access to the device. The vulnerability allows attackers to bypass authentication mechanisms and potentially take control of the router.

Exploiting this vulnerability allows attackers to gain full administrative access to the TOTOLINK CP450 router. Once accessed, they can modify network settings, redirect traffic, inject malicious code, or even disable the device entirely. Such unauthorized control can lead to network disruptions, data breaches, and exposure of sensitive information. In a worst-case scenario, the compromised router could be used as a launch point for further attacks on connected devices.

By using the S4E platform, users can stay ahead of potential threats by leveraging our comprehensive vulnerability scanning capabilities. Our platform automatically checks your network devices for known vulnerabilities like the hard-coded password issue in TOTOLINK CP450. Regular scans help you identify and mitigate risks before they are exploited. S4E provides actionable insights and remediation steps, empowering you to secure your digital assets with ease. Join our community to protect your network and enjoy peace of mind knowing that your devices are safeguarded.

References:

Solution Advice
  • Replace the TOTOLINK CP450 router with a newer model or alternative that does not contain hard-coded credentials.
  • Disable the Telnet service if it is not required, or block Telnet access from external networks.
  • Regularly update the router's firmware to the latest version provided by TOTOLINK.
  • Use strong, unique passwords for all device accounts and avoid using default or commonly known credentials.
  • Monitor network traffic for unusual activity that could indicate unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-7332 scanner - Hard-Coded Password vulnerability in TOTOLINK CP450 | S4E