PT-2020-10246 · Totolink+10 · Totolink N301Rt+17
Br0X
·
Published
2020-01-27
·
Updated
2020-02-06
·
CVE-2019-19823
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A3002RU versions 2.0.0 and earlier
TOTOLINK A702R versions 2.1.3 and earlier
TOTOLINK N301RT versions 2.1.6 and earlier
TOTOLINK N302R versions 3.4.0 and earlier
TOTOLINK N300RT versions 3.4.0 and earlier
TOTOLINK N200RE versions 4.0.0 and earlier
TOTOLINK N150RT versions 3.4.0 and earlier
TOTOLINK N100RE versions 3.4.0 and earlier
Rutek RTK 11N AP versions prior to 2019-12-12
Sapido GR297n versions prior to 2019-12-12
CIK TELECOM MESH ROUTER versions prior to 2019-12-12
KCTVJEJU Wireless AP versions prior to 2019-12-12
Fibergate FGN-R2 versions prior to 2019-12-12
Hi-Wifi MAX-C300N versions prior to 2019-12-12
HCN MAX-C300N versions prior to 2019-12-12
T-broad GN-866ac versions prior to 2019-12-12
Coship EMTA AP versions prior to 2019-12-12
IO-Data WN-AC1167R versions prior to 2019-12-12
Description
The router administration interface stores cleartext administrative passwords in flash memory and in a file. This issue affects various router models.
Recommendations
For TOTOLINK A3002RU versions 2.0.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK A702R versions 2.1.3 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK N301RT versions 2.1.6 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK N302R versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK N300RT versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK N200RE versions 4.0.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK N150RT versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For TOTOLINK N100RE versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files.
For Rutek RTK 11N AP versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For Sapido GR297n versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For CIK TELECOM MESH ROUTER versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For KCTVJEJU Wireless AP versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For Fibergate FGN-R2 versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For Hi-Wifi MAX-C300N versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For HCN MAX-C300N versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For T-broad GN-866ac versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For Coship EMTA AP versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
For IO-Data WN-AC1167R versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cik Telecom Mesh Router
Coship Emta Ap
Fibergate Fgn-R2
Hcn Max-C300N
Hi-Wifi Max-C300N
Io-Data Wn-Ac1167R
Kctvjeju Wireless Ap
Rutek Rtk 11N Ap
Sapido Gr297N
T-Broad Gn-866Ac
Totolink A3002Ru
Totolink A702R
Totolink N100Re
Totolink N150Rt
Totolink N200Re
Totolink N300Rt
Totolink N301Rt
Totolink N302R