7.5

CVE-2019-19822

Exploit
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Totolink ≫ A3002ru Firmware Version <= 2.0.0
   Totolink ≫ A3002ru Version -
Totolink ≫ A702r Firmware Version <= 2.1.3
   Totolink ≫ A702r Version -
Totolink ≫ N302r Firmware Version <= 3.4.0
   Totolink ≫ N302r Version -
Totolink ≫ N300rt Firmware Version <= 3.4.0
   Totolink ≫ N300rt Version -
Totolink ≫ N200re Firmware Version <= 4.0.0
   Totolink ≫ N200re Version -
Totolink ≫ N150rt Firmware Version <= 3.4.0
   Totolink ≫ N150rt Version -
Totolink ≫ N100re Firmware Version <= 3.4.0
   Totolink ≫ N100re Version -
Realtek ≫ Rtk 11n Ap Firmware Version <= 2019-12-12
   Realtek ≫ Rtk 11n Ap Version -
Sapido ≫ Gr297n Firmware Version <= 2019-12-12
   Sapido ≫ Gr297n Version -
Ciktel ≫ Mesh Router Firmware Version <= 2019-12-12
   Ciktel ≫ Mesh Router Version -
Kctvjeju ≫ Wireless Ap Firmware Version <= 2019-12-12
   Kctvjeju ≫ Wireless Ap Version -
Fg-products ≫ Fgn-r2 Firmware Version <= 2019-12-12
   Fg-products ≫ Fgn-r2 Version -
Hiwifi ≫ Max-c300n Firmware Version <= 2019-12-12
   Hiwifi ≫ Max-c300n Version -
Tbroad ≫ Gn-866ac Firmware Version <= 2019-12-12
   Tbroad ≫ Gn-866ac Version -
Coship ≫ Emta Ap Firmwre Version <= 2019-12-12
   Coship ≫ Emta Ap Version -
Iodata ≫ Wn-ac1167r Firmwre Version <= 2019-12-12
   Iodata ≫ Wn-ac1167r Version -
Totolink ≫ N301rt Firmware Version <= 2.1.6
   Totolink ≫ N301rt Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.67% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2020/Jan/36
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2020/Jan/38
Third Party Advisory
Exploit
Mailing List
https://sploit.tech
Third Party Advisory
http://opensource.actiontec.com/sourcecode/wcb3000x/wecb3000n_gpl_0.16.8.4.tgz
Third Party Advisory
Exploit
https://github.com/Saturn49/wecb/blob/755ce19a493c78270c04b5aaf39664f0cddbb420/rtl819x/users/boa/apmib/apmib.h#L13
Third Party Advisory