S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-19824 Scanner

CVE-2019-19824 scanner - OS Command Injection vulnerability in various TOTOLINK Realtek SDK based routers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-19824
8.8
CVSS

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
a3002ru_firmwareby totolink
0
a702r_firmwareby totolink
0
n301rt_firmwareby totolink
0
Updated Aug 21, 2026View on NVD →
Detail

TOTOLINK Realtek SDK based routers are popular networking devices used in homes, offices, and other areas where internet connectivity is needed. These routers offer various features such as WAN/LAN connectivity, wireless connectivity, firewalls, and others to help users connect to the internet with ease. The routers are known for their reliability and affordability, making them an ideal choice for many people.

However, recently, a vulnerability was detected in the routers that can allow an attacker to execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This vulnerability was assigned CVE-2019-19824, and it affects several models of TOTOLINK Realtek SDK based routers including A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.

If exploited, this vulnerability can lead to full control over the affected device's internals. Attackers can use this access to steal data, manipulate the device's settings, or even carry out further attacks on other devices connected to the router. This can be particularly dangerous in cases where the router is used to connect to sensitive networks or when the connected devices store confidential data.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. With real-time vulnerability alerts and customizable reporting, this platform provides an easy and effective way to stay ahead of security risks and keep digital assets secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of affected TOTOLINK Realtek SDK based routers can take the following precautions:

  • Update the router firmware to the latest version.
  • Ensure that remote access to the router is not enabled.
  • Avoid using default passwords and instead, set strong, unique passwords for all user accounts.
  • Use firewalls to limit access to the router from unauthorized IPs.
  • Consider replacing affected routers with those that do not have this vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-19824 scanner - OS Command Injection vulnerability in various TOTOLINK Realtek SDK based routers | S4E