Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
realtek sdk vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-27372
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow malicious users to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.
Realtek Xpon Rtl9601d Software Development Kit 1.9
8.8
CVSSv3
CVE-2022-29558
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
Realtek Rtl819x Software Development Kit
8.8
CVSSv3
CVE-2020-12773
A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.
Realtek Adsl Router Soc Firmware -
7.5
CVSSv3
CVE-2019-19822
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote malicious users to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU up to and including 2.0.0, A702R up to ...
Totolink A3002ru Firmware
Totolink A702r Firmware
Totolink N302r Firmware
Totolink N300rt Firmware
Totolink N200re Firmware
Totolink N150rt Firmware
Totolink N100re Firmware
Realtek Rtk 11n Ap Firmware
Sapido Gr297n Firmware
Ciktel Mesh Router Firmware
Kctvjeju Wireless Ap Firmware
Fg-products Fgn-r2 Firmware
Hiwifi Max-c300n Firmware
Tbroad Gn-866ac Firmware
Coship Emta Ap Firmwre
Iodata Wn-ac1167r Firmwre
Hcn Max-c300n Project Hcn Max-c300n Firmware
Totolink N301rt Firmware
1 Github repository
7.5
CVSSv3
CVE-2019-19823
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU up to and including 2.0.0, A702R up to and including 2.1.3, N301RT up to and in...
Totolink A3002ru Firmware
Totolink A702r Firmware
Totolink N302r Firmware
Totolink N300rt Firmware
Totolink N200re Firmware
Totolink N150rt Firmware
Totolink N100re Firmware
Realtek Rtk 11n Ap Firmware
Sapido Gr297n Firmware
Ciktel Mesh Router Firmware
Kctvjeju Wireless Ap Firmware
Fg-products Fgn-r2 Firmware
Hiwifi Max-c300n Firmware
Tbroad Gn-866ac Firmware
Coship Emta Ap Firmwre
Iodata Wn-ac1167r Firmwre
Hcn Max-c300n Project Hcn Max-c300n Firmware
Totolink N301rt Firmware
8.8
CVSSv3
CVE-2019-19824
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This aff...
Totolink A3002ru Firmware
Totolink A702r Firmware
Totolink N301rt Firmware
Totolink N302r Firmware
Totolink N300rt Firmware
Totolink N200re Firmware
Totolink N150rt Firmware
Totolink N100re Firmware
1 Github repository
9.8
CVSSv3
CVE-2019-19825
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid...
Totolink A3002ru Firmware
Totolink A702r Firmware
Totolink N301rt Firmware
Totolink N302r Firmware
Totolink N300rt Firmware
Totolink N200re Firmware
Totolink N150rt Firmware
Totolink N100re Firmware
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2