CVE-2019-19823
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 6.41% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- totolink/a3002ru firmware · totolink/a702r firmware · totolink/n302r firmware · totolink/n300rt firmware · totolink/n200re firmware · totolink/n150rt firmware · totolink/n100re firmware · realtek/rtk 11n ap firmware · sapido/gr297n firmware · ciktel/mesh router firmware · kctvjeju/wireless ap firmware · fg-products/fgn-r2 firmware · hiwifi/max-c300n firmware · tbroad/gn-866ac firmware · coship/emta ap firmwre · iodata/wn-ac1167r firmwre · hcn max-c300n project/hcn max-c300n firmware · totolink/n301rt firmware
- Source
- cve@mitre.org
References
- http://opensource.actiontec.com/sourcecode/wcb3000x/wecb3000n_gpl_0.16.8.4.tgzExploit, Third Party Advisory
- http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jan/36Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Jan/38Exploit, Mailing List, Third Party Advisory
- https://github.com/Saturn49/wecb/blob/755ce19a493c78270c04b5aaf39664f0cddbb420/rtl819x/users/boa/apmib/apmib.h#L13Third Party Advisory
- https://sploit.techThird Party Advisory
- http://opensource.actiontec.com/sourcecode/wcb3000x/wecb3000n_gpl_0.16.8.4.tgzExploit, Third Party Advisory
- http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jan/36Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Jan/38Exploit, Mailing List, Third Party Advisory
- https://github.com/Saturn49/wecb/blob/755ce19a493c78270c04b5aaf39664f0cddbb420/rtl819x/users/boa/apmib/apmib.h#L13Third Party Advisory
- https://sploit.techThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.