CVE-2019-19967 describes a critical vulnerability in Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices, where the administration page transmits passwords in cleartext via a POST request on port 80, specifically to the xml/setter.xml URI. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a severe risk due to its network-based attack vector and low attack complexity, allowing unauthorized disclosure of sensitive information. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been identified, the cleartext transmission of credentials presents a substantial security risk. Organizations using affected UPC Connect Box EuroDOCSIS firmware should prioritize remediation to prevent potential credential compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ch7465lg-ncip-6.12.18.25-2p6-noshCPE matchmatch criteria | cpe:2.3:o:upc:connect_box_eurodocsis_firmware:ch7465lg-ncip-6.12.18.25-2p6-nosh:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.