First published: Mon Jan 27 2020(Updated: )
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3002ru Firmware | <=2.0.0 | |
TOTOLINK A3002RU | ||
Totolink A702r Firmware | <=2.1.3 | |
Totolink A702r | ||
Totolink N301rt Firmware | <=2.1.6 | |
Totolink N301rt | ||
Totolink N302r Firmware | <=3.4.0 | |
Totolink N302r | ||
Totolink N300rt Firmware | <=3.4.0 | |
TOTOLINK N300RT | ||
Totolink N200re Firmware | <=4.0.0 | |
Totolink N200RE | ||
Totolink N150rt Firmware | <=3.4.0 | |
Totolink N150rt | ||
Totolink N100re Firmware | <=3.4.0 | |
Totolink N100re | ||
All of | ||
Totolink A3002ru Firmware | <=2.0.0 | |
TOTOLINK A3002RU | ||
All of | ||
Totolink A702r Firmware | <=2.1.3 | |
Totolink A702r | ||
All of | ||
Totolink N301rt Firmware | <=2.1.6 | |
Totolink N301rt | ||
All of | ||
Totolink N302r Firmware | <=3.4.0 | |
Totolink N302r | ||
All of | ||
Totolink N300rt Firmware | <=3.4.0 | |
TOTOLINK N300RT | ||
All of | ||
Totolink N200re Firmware | <=4.0.0 | |
Totolink N200RE | ||
All of | ||
Totolink N150rt Firmware | <=3.4.0 | |
Totolink N150rt | ||
All of | ||
Totolink N100re Firmware | <=3.4.0 | |
Totolink N100re |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2019-19824.
The severity level of CVE-2019-19824 is critical with a severity value of 8.8.
The TOTOLINK routers affected by CVE-2019-19824 are A3002RU with firmware up to version 2.0.0, A702r with firmware up to version 2.1.3, N301rt with firmware up to version 2.1.6, N302r with firmware up to version 3.4.0, N300rt with firmware up to version 3.4.0, N200re with firmware up to version 4.0.0, N150rt with firmware up to version 3.4.0, and N100re with firmware up to version 3.4.0.
The vulnerability CVE-2019-19824 allows an authenticated attacker to execute arbitrary OS commands by using the sysCmd parameter to the boafrm/formSysCmd URI.
At the moment, there are no known fixes or patches available for CVE-2019-19824. It is advised to take measures such as implementing strong access controls and network segmentation to mitigate the risk.