CVE-2019-19823: High severity totolink a3002ru vulnerability
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19823?
CVE-2019-19823 is a vulnerability in certain router administration interfaces where cleartext administrative passwords are stored in flash memory and in a file.
Which devices are affected by CVE-2019-19823?
TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0.
What is the severity of CVE-2019-19823?
The severity of CVE-2019-19823 is high with a CVSS score of 7.5.
How can I fix the CVE-2019-19823 vulnerability?
To fix the CVE-2019-19823 vulnerability, it is recommended to update the firmware of the affected devices to the latest version provided by the manufacturer.
Where can I find more information about CVE-2019-19823?
You can find more information about CVE-2019-19823 on the following references: [link1](http://opensource.actiontec.com/sourcecode/wcb3000x/wecb3000n_gpl_0.16.8.4.tgz), [link2](http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html), [link3](http://seclists.org/fulldisclosure/2020/Jan/36)