Impact
A flaw in the loginAuth function of the authentication handler allows an attacker to generate insufficiently random authentication tokens, making them predictable. This vulnerability enables remote attackers to forge valid login credentials and obtain unauthorized access to the device. It is tied to issues of limited entropy and weak cryptographic practices, as noted by CWE-310 and CWE-330.
Affected Systems
The vulnerability is specific to TOTOLINK N600R routers running firmware 4.3.0cu.7866_B20220506. No other affected versions are listed in the available data, so the risk applies to devices hosting that exact build.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. Nevertheless, the attack is possible remotely, requires relatively high complexity, and is considered difficult to exploit, but the potential impact of authentication bypass makes it a concern for operators.
OpenCVE Enrichment