7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Affected (18)
Products: Totolink: A3002ru Firmware, A702r Firmware, N302r Firmware, N300rt Firmware, N200re Firmware, N150rt Firmware, N100re Firmware, N301rt Firmware · Realtek: Rtk 11n Ap Firmware · Sapido: Gr297n Firmware · +8 more
Show all products
Totolink: A3002ru Firmware, A702r Firmware, N302r Firmware, N300rt Firmware, N200re Firmware, N150rt Firmware, N100re Firmware, N301rt Firmware · Realtek: Rtk 11n Ap Firmware · Sapido: Gr297n Firmware · Ciktel: Mesh Router Firmware · Kctvjeju: Wireless Ap Firmware · Fg Products: Fgn R2 Firmware · Hiwifi: Max C300n Firmware · Tbroad: Gn 866ac Firmware · Coship: Emta Ap Firmwre · Iodata: Wn Ac1167r Firmwre · Hcn Max C300n Project: Hcn Max C300n Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.0.0 |
| Running on/with | Platform Versions |
|---|---|
Totolink A3002ru | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.1.3 |
| Running on/with | Platform Versions |
|---|---|
Totolink A702r | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.4.0 |
| Running on/with | Platform Versions |
|---|---|
Totolink N302r | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.4.0 |
| Running on/with | Platform Versions |
|---|---|
Totolink N300rt | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.0.0 |
| Running on/with | Platform Versions |
|---|---|
Totolink N200re | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.4.0 |
| Running on/with | Platform Versions |
|---|---|
Totolink N150rt | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.4.0 |
| Running on/with | Platform Versions |
|---|---|
Totolink N100re | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Realtek Rtk 11n Ap | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Sapido Gr297n | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Ciktel Mesh Router | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Kctvjeju Wireless Ap | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Fg Products Fgn R2 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Hiwifi Max C300n | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Tbroad Gn 866ac | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Coship Emta Ap | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Iodata Wn Ac1167r | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2019-12-12 |
| Running on/with | Platform Versions |
|---|---|
Hcn Max C300n Project Hcn Max C300n | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.1.6 |
| Running on/with | Platform Versions |
|---|---|
Totolink N301rt | All versions |
References (12)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.