CVE-2019-25239 is an unauthenticated information disclosure vulnerability in V-SOL GPON/EPON OLT Platform 2.03. It allows attackers to download sensitive configuration files, such as usrcfg.conf, through direct object reference by sending HTTP GET requests. This vulnerability has a high severity CVSS score of 7.5, indicating it can be exploited remotely with low complexity and without authentication, potentially leading to authentication bypass and system access. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Guangzhou V-SOLUTION Electronic Technology | GPON/EPON OLT Platform | V1.4, V1.8.6, V2.03.24, V2.03.26, V2.03.40, V2.03.47, V2.03.49, V2.03.52R, V2.03.54R, V2.03.62R_IPv6CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.