devolo dLAN 500 AV Wireless+ 3.1.0-1 Remote Code Execution via htmlmgr
Vulnerability Description
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25249
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Stefan Petrushevski aka sm @zeroscience
References
Affected Vendor
devolo AG
View all reports →