CVE Feed

    Dashboard / CVE / CVE-2019-19825

    CVE-2019-19825

    On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.

    Published:Jan 27, 2020
    Last Modified:Nov 21, 2024
    EPS:Jan 27, 2020
    EPSS Score:0.00619
    CVSS Score:9.8

    Affected Products

    Vendor
    Totolink
    Product
    A3002ru
    Vendor
    Totolink
    Product
    A3002ru Firmware
    Vendor
    Totolink
    Product
    A702r
    Vendor
    Totolink
    Product
    A702r Firmware
    Vendor
    Totolink
    Product
    N100re
    Vendor
    Totolink
    Product
    N100re Firmware
    Vendor
    Totolink
    Product
    N150rt
    Vendor
    Totolink
    Product
    N150rt Firmware
    Vendor
    Totolink
    Product
    N200re
    Vendor
    Totolink
    Product
    N200re Firmware
    Vendor
    Totolink
    Product
    N300rt
    Vendor
    Totolink
    Product
    N300rt Firmware
    Vendor
    Totolink
    Product
    N301rt
    Vendor
    Totolink
    Product
    N301rt Firmware
    Vendor
    Totolink
    Product
    N302r
    Vendor
    Totolink
    Product
    N302r Firmware

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High