CVE-2019-19824
totolink a3002ru Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2019-19824 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 11, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2024 · Source: CVE List
Affected products and versions
9| Product | Source | Version range | Status |
|---|---|---|---|
a3002ruBrowse totolink / a3002ru | VulnCheck | Version data not supplied | |
a3002ru_firmwareBrowse totolink / a3002ru_firmwareDefault status: unknown | CVE List | Through 2.0.0 | affected |
a702r_firmwareBrowse totolink / a702r_firmwareDefault status: unknown | CVE List | Through 2.1.3 | affected |
n100re_firmwareBrowse totolink / n100re_firmwareDefault status: unknown | CVE List | Through 3.4.0 | affected |
n150rt_firmwareBrowse totolink / n150rt_firmwareDefault status: unknown | CVE List | Through 3.4.0 | affected |
n200re_firmwareBrowse totolink / n200re_firmwareDefault status: unknown | CVE List | Through 4.0.0 | affected |
n301rt_firmwareBrowse totolink / n301rt_firmwareDefault status: unknown | CVE List | Through 2.1.6 | affected |
n302r_firmwareBrowse totolink / n302r_firmwareDefault status: unknown | CVE List | Through 3.4.0 | affected |
n302re_firmwareBrowse totolink / n302re_firmwareDefault status: unknown | CVE List | Before 2.0.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHTOTOLINK Realtek SD Routers - Remote Command InjectionCVSS 8.8
TOTOLINK Realtek SDK based routers may allow an authenticated attacker to execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.
Remediation
Apply the latest firmware update provided by the vendor to fix the vulnerability.
Source: ProjectDiscovery