{"id": "CVE-2019-19824", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 9.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C", "authentication": "SINGLE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2020-01-27T18:15:12.960", "references": [{"url": "http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "http://seclists.org/fulldisclosure/2020/Jan/36", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://seclists.org/fulldisclosure/2020/Jan/38", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/yckuo-sdc/totolink-boa-api-vulnerabilities", "source": "cve@mitre.org"}, {"url": "https://sploit.tech", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://seclists.org/fulldisclosure/2020/Jan/36", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://seclists.org/fulldisclosure/2020/Jan/38", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://sploit.tech", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-78"}]}], "descriptions": [{"lang": "en", "value": "On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2."}, {"lang": "es", "value": "En determinados enrutadores basados ??en TOTOLINK Realtek SDK, un atacante autenticado puede ejecutar comandos arbitrarios de Sistema Operativo por medio del par\u00e1metro sysCmd en el URI boafrm/formSysCmd, inclusive si la GUI (syscmd.htm) no est\u00e1 disponible. Esto permite un control total sobre los internos del dispositivo. Esto afecta a A3002RU versiones hasta 2.0.0, A702R versiones hasta 2.1.3, N301RT versiones hasta 2.1.6, N302R versiones hasta 3.4.0, N300RT versiones hasta 3.4.0, N200RE versiones hasta 4.0.0, N150RT versiones hasta 3.4.0 y N100RE versiones hasta 3.4.0."}], "lastModified": "2024-11-21T04:35:28.233", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:a3002ru_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87EC51C9-338B-4E98-8455-069319320802", "versionEndIncluding": "2.0.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:a3002ru:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "21945D3C-27AA-4614-8D5D-C22DE8C56F94"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:a702r_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28C67D43-7914-4AF3-9DF8-E1BF41F1AC89", "versionEndIncluding": "2.1.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:a702r:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "49D3C58B-4632-464E-A0A6-33807E9A1842"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:n301rt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87A0ECEA-3FA7-4ADF-ACFA-6C4B93373DA3", "versionEndIncluding": "2.1.6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:n301rt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EE1ED560-8B9F-40D2-AD91-6D5D4290ED79"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:n302r_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71A22EA9-F5A5-4789-96F4-3C8600BC4848", "versionEndIncluding": "3.4.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:n302r:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D0E1D2C0-02F5-4933-9DEB-89F711052D69"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:n300rt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E826FD1-C8F6-4301-972F-1B3949F59275", "versionEndIncluding": "3.4.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:n300rt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F0581174-E6B1-4E3D-8384-7852EC53FC14"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:n200re_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47025B3A-648B-4F89-AEA0-C76B348CBAFB", "versionEndIncluding": "4.0.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:n200re:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9FF7FF59-DB13-4FEA-A81C-124048BF1676"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:n150rt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E096F9E2-08E5-4B44-A83A-FB659D898DB5", "versionEndIncluding": "3.4.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:n150rt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7525BE05-F394-4ED7-B7A6-F9005EDE90D7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:totolink:n100re_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "635C33EA-BEF1-4C7E-8E3A-5ED5DF79358D", "versionEndIncluding": "3.4.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:totolink:n100re:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "30CA1251-C9EA-498E-9AD4-627CA9B1A007"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}