CVE-2019-3916 is an information disclosure vulnerability affecting Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05, allowing an unauthenticated attacker to retrieve the password salt via a simple API request. Rated 7.5 HIGH on CVSS, this vulnerability is easily exploitable remotely with low complexity, potentially leading to unauthorized access if the salt is used in conjunction with other leaked credentials. While not listed in CISA's KEV catalog, it has received media coverage and community discussion, indicating awareness, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
02.01.00.05CPE matchmatch criteria | cpe:2.3:o:verizon:fios_quantum_gateway_g1100_firmware:02.01.00.05:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019