Cross-Site Request Forgery in Devolo dLAN 500 AV Wireless+
CVE-2019-25250
Key Information:
- Vendor
Devolo Ag
- Vendor
- CVE Published:
- 24 December 2025
Badges
What is CVE-2019-25250?
The Devolo dLAN 500 AV Wireless+ version 3.1.0-1 is susceptible to a cross-site request forgery vulnerability. This flaw permits attackers to execute unauthorized administrative actions by leveraging predictable URL structures. If a logged-in user inadvertently visits a specially crafted malicious webpage, it can trigger undesired configuration alterations within the device, potentially compromising the overall security of the network.
Affected Version(s)
dLAN 550 duo+ Starter Kit 500 AV Wireless+ 3.1.0-1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
