devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters. | |
| Title | devolo dLAN 500 AV Wireless+ 3.1.0-1 Remote Code Execution via htmlmgr | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:22:26.831Z
Reserved: 2025-12-24T14:27:12.477Z
Link: CVE-2019-25249
Updated: 2025-12-24T20:02:27.707Z
Status : Received
Published: 2025-12-24T20:15:53.247
Modified: 2025-12-24T21:16:02.890
Link: CVE-2019-25249
No data.
OpenCVE Enrichment
No data.