CVE-2019-19824 - CVE House
Back to Database
Status published High CVE-2019-19824

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker...

Vulnerability Description

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19824

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

a3002ru firmware, a702r firmware, n301rt firmware, n302r firmware, n300rt firmware, n200re firmware, n150rt firmware, n100re firmware
Vulnerable Versions:
0

Timeline

Official Publish: January 27th, 2020
Last Modified: August 28th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.