Unauthenticated File Disclosure in Across DR-810 by Across
CVE-2019-25706
Key Information:
Badges
What is CVE-2019-25706?
Across DR-810 contains a vulnerability that enables remote attackers to exploit an unauthenticated file disclosure issue. By sending a simple GET request, unauthorized individuals can access the rom-0 endpoint, which allows them to download a backup file containing sensitive information, such as router passwords and critical configuration data. This vulnerability poses a significant security risk as it enables attackers to exploit exposed information without requiring any form of authentication. Organizations using Across DR-810 are advised to take immediate action to mitigate this vulnerability.
Affected Version(s)
DR-810 ROM-0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
