CVE-2019-15064 is a critical authentication bypass vulnerability affecting HiNet GPON firmware versions prior to I040GWR190731, allowing unauthenticated attackers to log into affected devices. With a CVSS score of 9.8, this flaw presents a severe risk, enabling full compromise (confidentiality, integrity, and availability) with low attack complexity over the network. Despite its critical severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog. Community discussion and media coverage for this vulnerability are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< i040gwr190731CPE matchmatch criteria | cpe:2.3:o:hinet:gpon_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.