CVE Feed

    Dashboard / CVE / CVE-2019-19824

    CVE-2019-19824

    On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

    Published:Jan 27, 2020
    Last Modified:Nov 21, 2024
    EPS:Jan 27, 2020
    EPSS Score:0.93672
    CVSS Score:8.8

    Affected Products

    Vendor
    Totolink
    Product
    A3002ru
    Vendor
    Totolink
    Product
    A3002ru Firmware
    Vendor
    Totolink
    Product
    A702r
    Vendor
    Totolink
    Product
    A702r Firmware
    Vendor
    Totolink
    Product
    N100re
    Vendor
    Totolink
    Product
    N100re Firmware
    Vendor
    Totolink
    Product
    N150rt
    Vendor
    Totolink
    Product
    N150rt Firmware
    Vendor
    Totolink
    Product
    N200re
    Vendor
    Totolink
    Product
    N200re Firmware
    Vendor
    Totolink
    Product
    N300rt
    Vendor
    Totolink
    Product
    N300rt Firmware
    Vendor
    Totolink
    Product
    N301rt
    Vendor
    Totolink
    Product
    N301rt Firmware
    Vendor
    Totolink
    Product
    N302r
    Vendor
    Totolink
    Product
    N302r Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High