CVE-2019-25249

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-24 20:15

Updated : 2025-12-29 15:58


NVD link : CVE-2019-25249

Mitre link : CVE-2019-25249

CVE.ORG link : CVE-2019-25249


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment