PT-2020-10248 · Totolink+1 · Totolink N301Rt+8
Blazej Adamczyk
+1
·
Published
2020-01-27
·
Updated
2020-02-05
·
CVE-2019-19825
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A3002RU versions 2.0.0 and earlier
TOTOLINK A702R versions 2.1.3 and earlier
TOTOLINK N301RT versions 2.1.6 and earlier
TOTOLINK N302R versions 3.4.0 and earlier
TOTOLINK N300RT versions 3.4.0 and earlier
TOTOLINK N200RE versions 4.0.0 and earlier
TOTOLINK N150RT versions 3.4.0 and earlier
TOTOLINK N100RE versions 3.4.0 and earlier
Description
The issue allows an attacker to bypass the CAPTCHA protection on certain TOTOLINK Realtek SDK based routers. This can be achieved by sending a POST request to the "boafrm/formLogin" URI with a specific
topicurl parameter set to "setting/getSanvas", which retrieves the CAPTCHA text. Once valid credentials are obtained, the attacker can perform router actions via HTTP requests using Basic Authentication.Recommendations
For TOTOLINK A3002RU versions 2.0.0 and earlier, update to a version later than 2.0.0.
For TOTOLINK A702R versions 2.1.3 and earlier, update to a version later than 2.1.3.
For TOTOLINK N301RT versions 2.1.6 and earlier, update to a version later than 2.1.6.
For TOTOLINK N302R versions 3.4.0 and earlier, update to a version later than 3.4.0.
For TOTOLINK N300RT versions 3.4.0 and earlier, update to a version later than 3.4.0.
For TOTOLINK N200RE versions 4.0.0 and earlier, update to a version later than 4.0.0.
For TOTOLINK N150RT versions 3.4.0 and earlier, update to a version later than 3.4.0.
For TOTOLINK N100RE versions 3.4.0 and earlier, update to a version later than 3.4.0.
As a temporary workaround, consider restricting access to the "boafrm/formLogin" URI and disabling Basic Authentication until a patch is available.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realtek Sdk
Totolink A3002Ru
Totolink A702R
Totolink N100Re
Totolink N150Rt
Totolink N200Re
Totolink N300Rt
Totolink N301Rt
Totolink N302R