V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 20:15
Updated : 2025-12-29 15:58
NVD link : CVE-2019-25239
Mitre link : CVE-2019-25239
CVE.ORG link : CVE-2019-25239
JSON object : View
Products Affected
No product.
CWE
CWE-552
Files or Directories Accessible to External Parties
