PT-2020-10245 · Totolink+11 · Totolink N301Rt+18
Br0X
·
Published
2020-01-27
·
Updated
2020-08-24
·
CVE-2019-19822
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A3002RU versions 2.0.0 and earlier
TOTOLINK A702R versions 2.1.3 and earlier
TOTOLINK N301RT versions 2.1.6 and earlier
TOTOLINK N302R versions 3.4.0 and earlier
TOTOLINK N300RT versions 3.4.0 and earlier
TOTOLINK N200RE versions 4.0.0 and earlier
TOTOLINK N150RT versions 3.4.0 and earlier
TOTOLINK N100RE versions 3.4.0 and earlier
Rutek RTK 11N AP versions prior to 2019-12-12
Sapido GR297n versions prior to 2019-12-12
CIK TELECOM MESH ROUTER versions prior to 2019-12-12
KCTVJEJU Wireless AP versions prior to 2019-12-12
Fibergate FGN-R2 versions prior to 2019-12-12
Hi-Wifi MAX-C300N versions prior to 2019-12-12
HCN MAX-C300N versions prior to 2019-12-12
T-broad GN-866ac versions prior to 2019-12-12
Coship EMTA AP versions prior to 2019-12-12
IO-Data WN-AC1167R versions prior to 2019-12-12
Description
The router administration interface, which includes Realtek APMIB 0.11f for Boa 0.94.14rc21, allows remote attackers to retrieve the configuration, including sensitive data such as usernames and passwords.
Recommendations
For TOTOLINK A3002RU versions 2.0.0 and earlier, update to a version later than 2.0.0.
For TOTOLINK A702R versions 2.1.3 and earlier, update to a version later than 2.1.3.
For TOTOLINK N301RT versions 2.1.6 and earlier, update to a version later than 2.1.6.
For TOTOLINK N302R versions 3.4.0 and earlier, update to a version later than 3.4.0.
For TOTOLINK N300RT versions 3.4.0 and earlier, update to a version later than 3.4.0.
For TOTOLINK N200RE versions 4.0.0 and earlier, update to a version later than 4.0.0.
For TOTOLINK N150RT versions 3.4.0 and earlier, update to a version later than 3.4.0.
For TOTOLINK N100RE versions 3.4.0 and earlier, update to a version later than 3.4.0.
For Rutek RTK 11N AP versions prior to 2019-12-12, update to a version later than 2019-12-12.
For Sapido GR297n versions prior to 2019-12-12, update to a version later than 2019-12-12.
For CIK TELECOM MESH ROUTER versions prior to 2019-12-12, update to a version later than 2019-12-12.
For KCTVJEJU Wireless AP versions prior to 2019-12-12, update to a version later than 2019-12-12.
For Fibergate FGN-R2 versions prior to 2019-12-12, update to a version later than 2019-12-12.
For Hi-Wifi MAX-C300N versions prior to 2019-12-12, update to a version later than 2019-12-12.
For HCN MAX-C300N versions prior to 2019-12-12, update to a version later than 2019-12-12.
For T-broad GN-866ac versions prior to 2019-12-12, update to a version later than 2019-12-12.
For Coship EMTA AP versions prior to 2019-12-12, update to a version later than 2019-12-12.
For IO-Data WN-AC1167R versions prior to 2019-12-12, update to a version later than 2019-12-12.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cik Telecom Mesh Router
Coship Emta Ap
Fibergate Fgn-R2
Hcn Max-C300N
Hi-Wifi Max-C300N
Io-Data Wn-Ac1167R
Kctvjeju Wireless Ap
Realtek Apmib
Rutek Rtk 11N Ap
Sapido Gr297N
T-Broad Gn-866Ac
Totolink A3002Ru
Totolink A702R
Totolink N100Re
Totolink N150Rt
Totolink N200Re
Totolink N300Rt
Totolink N301Rt
Totolink N302R