9
CVSSv2

CVE-2019-19824

Published: 27/01/2020 Updated: 05/02/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU up to and including 2.0.0, A702R up to and including 2.1.3, N301RT up to and including 2.1.6, N302R up to and including 3.4.0, N300RT up to and including 3.4.0, N200RE up to and including 4.0.0, N150RT up to and including 3.4.0, and N100RE up to and including 3.4.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

totolink a3002ru_firmware

totolink a702r_firmware

totolink n301rt_firmware

totolink n302r_firmware

totolink n300rt_firmware

totolink n200re_firmware

totolink n150rt_firmware

totolink n100re_firmware

Exploits

Realtek SDK based routers suffer from information disclosure, incorrect access control, insecure password storage, code execution, and incorrectly implemented CAPTCHA vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Multiple vulnerabilities in TOTOLINK and other Realtek SDK based routers <!--X-Subject-Header-End--> <!--X-Head-of-Mes ...

Github Repositories

Totolink N200RE remote root exploit

totoroot Totolink N200RE remote root exploit Disclaimer I know that the code isn't perfect Please don't learn from it or better don't read it at all Supported devices Totolink N200RE-V3 Mini and probably other Totolink devices vulnerable to CVE-2019-19822, CVE-2019-19824 and related How to use curl rawgithubusercontentcom/lkkula/totoroot/main/totoro