Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-15119

19
FAUCET Score

CVE-2019-15119 is a file permission vulnerability affecting cnlh nps versions up to 0.23.2, where the installer sets overly permissive 0777 permissions for the nps executable in /usr/local/bin or /usr/bin. This allows a local user to overwrite the nps executable, potentially leading to unauthorized code execution. The vulnerability has a CVSS score of 5.5 (Medium) with a local attack vector and low attack complexity, but requires user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.23.2CPE matchmatch criteria
cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.95%
Probability of exploitation in next 30 days
EPSS Percentile
57.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0095 is in the 68th percentile among its peer group of 5,758 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: ehang.io/npsFixed in: 0.23.2

Vendor Advisories (1)

goGHSA-2vp2-8m5j-4rjxmedium

cnlh nps vulnerable to file overwrite by local user

May 24, 2022

References

github.com / cnlh/nps/commit/7178b3380720e910d283036a8d39879a94105515
PatchThird Party Advisory
github.com / cnlh/nps/issues/176
ExploitThird Party Advisory