← All CVEs

CVE-2019-19825

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.

9.8
CVSS
29.6%
EPSS (exploit prob.)
98th
EPSS percentile
2020-01-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
totolinka3002ru_firmware<= 2.0.0
totolinka3002ruall versions
totolinka702r_firmware<= 2.1.3
totolinka702rall versions
totolinkn301rt_firmware<= 2.1.6
totolinkn301rtall versions
totolinkn302r_firmware<= 3.4.0
totolinkn302rall versions
totolinkn300rt_firmware<= 3.4.0
totolinkn300rtall versions
totolinkn200re_firmware<= 4.0.0
totolinkn200reall versions
totolinkn150rt_firmware<= 3.4.0
totolinkn150rtall versions
totolinkn100re_firmware<= 3.4.0
totolinkn100reall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-19825