CVE-2019-25239

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-24 20:15

Updated : 2025-12-29 15:58


NVD link : CVE-2019-25239

Mitre link : CVE-2019-25239

CVE.ORG link : CVE-2019-25239


JSON object : View

Products Affected

No product.

CWE
CWE-552

Files or Directories Accessible to External Parties