PT-2020-10246 · Totolink+10 · Totolink N301Rt+17

Br0X

·

Published

2020-01-27

·

Updated

2020-02-06

·

CVE-2019-19823

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK A3002RU versions 2.0.0 and earlier TOTOLINK A702R versions 2.1.3 and earlier TOTOLINK N301RT versions 2.1.6 and earlier TOTOLINK N302R versions 3.4.0 and earlier TOTOLINK N300RT versions 3.4.0 and earlier TOTOLINK N200RE versions 4.0.0 and earlier TOTOLINK N150RT versions 3.4.0 and earlier TOTOLINK N100RE versions 3.4.0 and earlier Rutek RTK 11N AP versions prior to 2019-12-12 Sapido GR297n versions prior to 2019-12-12 CIK TELECOM MESH ROUTER versions prior to 2019-12-12 KCTVJEJU Wireless AP versions prior to 2019-12-12 Fibergate FGN-R2 versions prior to 2019-12-12 Hi-Wifi MAX-C300N versions prior to 2019-12-12 HCN MAX-C300N versions prior to 2019-12-12 T-broad GN-866ac versions prior to 2019-12-12 Coship EMTA AP versions prior to 2019-12-12 IO-Data WN-AC1167R versions prior to 2019-12-12
Description The router administration interface stores cleartext administrative passwords in flash memory and in a file. This issue affects various router models.
Recommendations For TOTOLINK A3002RU versions 2.0.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK A702R versions 2.1.3 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK N301RT versions 2.1.6 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK N302R versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK N300RT versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK N200RE versions 4.0.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK N150RT versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For TOTOLINK N100RE versions 3.4.0 and earlier, update the firmware to remove cleartext administrative passwords from flash memory and files. For Rutek RTK 11N AP versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For Sapido GR297n versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For CIK TELECOM MESH ROUTER versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For KCTVJEJU Wireless AP versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For Fibergate FGN-R2 versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For Hi-Wifi MAX-C300N versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For HCN MAX-C300N versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For T-broad GN-866ac versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For Coship EMTA AP versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12. For IO-Data WN-AC1167R versions prior to 2019-12-12, update the firmware to a version released after 2019-12-12.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19823

Affected Products

Cik Telecom Mesh Router
Coship Emta Ap
Fibergate Fgn-R2
Hcn Max-C300N
Hi-Wifi Max-C300N
Io-Data Wn-Ac1167R
Kctvjeju Wireless Ap
Rutek Rtk 11N Ap
Sapido Gr297N
T-Broad Gn-866Ac
Totolink A3002Ru
Totolink A702R
Totolink N100Re
Totolink N150Rt
Totolink N200Re
Totolink N300Rt
Totolink N301Rt
Totolink N302R