V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access. | |
| Title | V-SOL GPON/EPON OLT Platform 2.03 Unauthenticated Configuration Download | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:23:32.107Z
Reserved: 2025-12-24T14:27:12.476Z
Link: CVE-2019-25239
No data.
Status : Received
Published: 2025-12-24T20:15:51.690
Modified: 2025-12-24T21:16:01.760
Link: CVE-2019-25239
No data.
OpenCVE Enrichment
No data.