HIGH · 7.5

CVE-2019-19823

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU...

Vulnerability Description

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
TotolinkA3002Ru Firmware<= 2.0.0
TotolinkA3002Ru-
TotolinkA702R Firmware<= 2.1.3
TotolinkA702R-
TotolinkN302R Firmware<= 3.4.0
TotolinkN302R-
TotolinkN300Rt Firmware<= 3.4.0
TotolinkN300Rt-
TotolinkN200Re Firmware<= 4.0.0
TotolinkN200Re-
TotolinkN150Rt Firmware<= 3.4.0
TotolinkN150Rt-
TotolinkN100Re Firmware<= 3.4.0
TotolinkN100Re-
RealtekRtk 11N Ap Firmware<= 2019-12-12
RealtekRtk 11N Ap-
SapidoGr297N Firmware<= 2019-12-12
SapidoGr297N-
CiktelMesh Router Firmware<= 2019-12-12
CiktelMesh Router-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-19823?

CVE-2019-19823 is a vulnerability with a CVSS score of 7.5 (HIGH). A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU...

How severe is CVE-2019-19823?

CVE-2019-19823 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-19823?

Check the references section above for vendor advisories and patch information. Affected products include: Totolink A3002Ru Firmware, Totolink A3002Ru, Totolink A702R Firmware, Totolink A702R, Totolink N302R Firmware.