CVE-2019-25706 is an unauthenticated file disclosure vulnerability affecting Across DR-810 routers that allows remote attackers to download the rom-0 backup file containing sensitive configuration data and router passwords via a simple GET request to an unprotected endpoint. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, reflecting its network-accessible attack vector, low complexity, and lack of authentication requirements, though impact is limited to confidentiality compromise with no integrity or availability effects. The exploitation status indicates this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows low community attention with an EPSS score of 0.0005, suggesting minimal active exploitation in the wild despite the technical simplicity of the attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Across | DR-810 | ROM-0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.