Open Redirect Vulnerability in V-SOL GPON/EPON OLT Platform
CVE-2019-25282
Key Information:
- Vendor
Guangzhou V
- Vendor
- CVE Published:
- 7 January 2026
Badges
What is CVE-2019-25282?
The V-SOL GPON/EPON OLT Platform version 2.03 is susceptible to an open redirect vulnerability due to improper validation of user input in its redirect mechanism. This flaw enables attackers to craft deceptive links that exploit the functionality of the 'parent' GET parameter. When exploited, logged-in users can be redirected to malicious external websites, posing risks such as phishing attacks and credential theft. Organizations using this platform are advised to implement proper input validation mechanisms to safeguard against this vulnerability.
Affected Version(s)
V-SOL GPON/EPON OLT Platform V2.03.62R_IPv6
V-SOL GPON/EPON OLT Platform V2.03.54R
V-SOL GPON/EPON OLT Platform V2.03.52R
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
