S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Nov 21, 2025

CVE-2019-19823 Scanner

CVE-2019-19823 Scanner - Information Disclosure vulnerability in TOTOLINK/Realtek Routers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-19823
7.5
CVSS

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

These routers, commonly used for residential and small business networking, are produced by TOTOLINK and utilize Realtek SDK firmware for network management. Networking professionals, IT administrators, and home users typically deploy these devices due to their affordability and basic configuration capabilities. Their primary use is to provide internet connectivity and local network management among connected devices. The popularity of these routers is due to their relative ease of setup and operation for non-expert users. The routers offer standard security features but may become susceptible to vulnerabilities when default configurations are left unchanged. Understanding the risk of this device is vital for maintaining network security and preventing unauthorized access.

The vulnerability present in the TOTOLINK/Realtek routers can result in unauthorized data disclosure. Remote attackers could potentially exploit this flaw to access sensitive information, including configuration settings and credentials, without authorization. Failure to address such vulnerabilities could lead to network interception or further attacks. This flaw primarily arises due to the insecure default settings in the router's firmware, specifically concerning access to the "config.dat" file. An attacker only requires network access to attempt an exploitation, which could compromise the entire network's security. Identifying these risks highlights the importance of updating firmware and configuring routers securely.

Technically, the vulnerability exists because accessible endpoints such as "/config.dat" expose sensitive data, which should typically require proper authentication. In these routers, the absence of checks allows unprotected downloads of configuration files. The exploitation involves sending a straightforward HTTP GET request to retrieve this configuration. Critical indicators include HTTP responses containing plain-text configurations and server information as "boa." The presence of these markers signifies that the accessed data includes sensitive router settings. The vulnerability consequently lies in both the insecure implementation of configuration file access and insufficient validation mechanisms.

Once exploited, this vulnerability could significantly impact the network's security posture. Attackers gaining access to the router's configuration can lead to unauthorized modifications, exposure of network details, and potential downstream attacks. Such exposures form a stepping stone to intercept data packets or deploy threat vectors across a compromised network. The risk extends to potential service disruptions and device misconfigurations, affecting both functionality and security. Proactively addressing these issues can prevent unauthorized data access and fortify the network against adversaries.

REFERENCES

Solution Advice
  • Update the router's firmware to the latest version provided by the manufacturer to address this vulnerability.
  • Disable unauthenticated access to sensitive configuration files such as "config.dat".
  • Regularly audit and change device management credentials to prevent unauthorized access.
  • Implement network segmentation to minimize the impact of any potential data disclosures.
  • Consider replacing the device if it does not receive frequent firmware updates or security patches from the vendor.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-19823 Scanner - Information Disclosure vulnerability in TOTOLINK/Realtek Routers | S4E