← Back

CVE-2019-19823

Published: Jan 27, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.

Affected (18)

Show all products
8 products
A3002ru Firmware
A702r Firmware
N302r Firmware
N300rt Firmware
N200re Firmware
N150rt Firmware
N100re Firmware
N301rt Firmware
1 product
Rtk 11n Ap Firmware
1 product
Gr297n Firmware
1 product
Mesh Router Firmware
1 product
Wireless Ap Firmware
1 product
Fgn R2 Firmware
1 product
Max C300n Firmware
1 product
Gn 866ac Firmware
1 product
Emta Ap Firmwre
1 product
Wn Ac1167r Firmwre
Hcn Max C300n Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.0.0
Running on/withPlatform Versions
Totolink
A3002ru
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.1.3
Running on/withPlatform Versions
Totolink
A702r
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.4.0
Running on/withPlatform Versions
Totolink
N302r
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.4.0
Running on/withPlatform Versions
Totolink
N300rt
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.0.0
Running on/withPlatform Versions
Totolink
N200re
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.4.0
Running on/withPlatform Versions
Totolink
N150rt
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.4.0
Running on/withPlatform Versions
Totolink
N100re
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Realtek
Rtk 11n Ap
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Sapido
Gr297n
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Ciktel
Mesh Router
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Kctvjeju
Wireless Ap
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Fg Products
Fgn R2
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Hiwifi
Max C300n
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Tbroad
Gn 866ac
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Coship
Emta Ap
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Iodata
Wn Ac1167r
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2019-12-12
Running on/withPlatform Versions
Hcn Max C300n Project
Hcn Max C300n
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.1.6
Running on/withPlatform Versions
Totolink
N301rt
All versions

References (12)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.