CAPTCHA Bypass Vulnerability in TOTOLINK Realtek SDK Based Routers
CVE-2019-19825
9.8CRITICAL
Summary
Certain TOTOLINK routers that utilize Realtek SDK exhibit a vulnerability that allows an attacker to bypass CAPTCHA protections. By exploiting a specific POST request to the boafrm/formLogin endpoint, an adversary can retrieve the CAPTCHA text without needing to validate it. Once valid credentials are known, the CAPTCHA serves no further purpose, enabling an attacker to perform administrative actions on the router via Basic Authentication. The affected product line includes models A3002RU, A702R, N301RT, N302R, N300RT, N200RE, N150RT, and N100RE across various firmware versions.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved