A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords)
Published Jan 27, 2020
7.5
HIGHCVSS 3.1
EPSS 8.67%
Description
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Affected products
No data.
Configuration 1
- ≤ 2.0.0
Configuration 2
- ≤ 2.1.3
Configuration 3
- ≤ 3.4.0
Configuration 4
- ≤ 3.4.0
Configuration 5
- ≤ 4.0.0
Configuration 6
- ≤ 3.4.0
Configuration 7
- ≤ 3.4.0
Configuration 8
- ≤ 2019-12-12
Running on/with
- n/a
Configuration 9
- ≤ 2019-12-12
Configuration 10
- ≤ 2019-12-12
Running on/with
- n/a
Configuration 11
- ≤ 2019-12-12
Running on/with
- n/a
Configuration 12
- ≤ 2019-12-12
Running on/with
- n/a
Configuration 13
- ≤ 2019-12-12
Configuration 14
- ≤ 2019-12-12
Configuration 15
- ≤ 2019-12-12
Configuration 16
- ≤ 2019-12-12
Running on/with
- n/a
Configuration 17
- ≤ 2019-12-12
Running on/with
- n/a
Configuration 18
- ≤ 2.1.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- http://opensource.actiontec.com/sourcecode/wcb3000x/wecb3000n_gpl_0.16.8.4.tgz x_refsource_MISCExploitThird Party Advisory
- http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jan/36 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Jan/38 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9420 Advisory
- https://github.com/Saturn49/wecb/blob/755ce19a493c78270c04b5aaf39664f0cddbb420/rtl819x/users/boa/apmib/apmib.h#L13 x_refsource_MISCThird Party Advisory
- https://sploit.tech x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://opensource.actiontec.com/sourcecode/wcb3000x/wecb3000n_gpl_0.16.8.4.tgz | x_refsource_MISCExploitThird Party Advisory | |
| http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://seclists.org/fulldisclosure/2020/Jan/36 | mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory | |
| http://seclists.org/fulldisclosure/2020/Jan/38 | mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9420 | Advisory | |
| https://github.com/Saturn49/wecb/blob/755ce19a493c78270c04b5aaf39664f0cddbb420/rtl819x/users/boa/apmib/apmib.h#L13 | x_refsource_MISCThird Party Advisory | |
| https://sploit.tech | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.