CVE-2019-19822: Ciktel Mesh Router Firmware
High severity, CVSS 7.5. EPSS: 8.7% chance of exploitation in the next 30 days.
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Affected products
- Ciktel Mesh Router Firmware: up to and including 2019-12-12
- Coship Emta Ap Firmwre: up to and including 2019-12-12
- Fg-Products Fgn-r2 Firmware: up to and including 2019-12-12
- Hcn Max-c300n Project Hcn Max-c300n Firmware: up to and including 2019-12-12
- Hiwifi Max-c300n Firmware: up to and including 2019-12-12
- Iodata Wn-AC1167R Firmwre: up to and including 2019-12-12
- Kctvjeju Wireless Ap Firmware: up to and including 2019-12-12
- Realtek Rtk 11n Ap Firmware: up to and including 2019-12-12
- Sapido GR297N Firmware: up to and including 2019-12-12
- Tbroad Gn-866ac Firmware: up to and including 2019-12-12
- Totolink a3002ru Firmware: up to and including 2.0.0
- Totolink a702r Firmware: up to and including 2.1.3
- Totolink n100re Firmware: up to and including 3.4.0
- Totolink n150rt Firmware: up to and including 3.4.0
- Totolink n200re Firmware: up to and including 4.0.0
- Totolink n300rt Firmware: up to and including 3.4.0
- Totolink n301rt Firmware: up to and including 2.1.6
- Totolink n302r Firmware: up to and including 3.4.0
Published 2020-01-27. Last modified 2026-06-17.