CVE-2019-6279 describes an Incorrect Access Control vulnerability in ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with W2001EN-00 firmware. This flaw allows an unauthenticated attacker to change the wireless security password by directly accessing a specific URI. Rated 8.8 HIGH on the CVSS scale, this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to high impacts on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
w2001en-00CPE matchmatch criteria | cpe:2.3:o:chinamobileltd:gpn2.4p21-c-cn_firmware:w2001en-00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.