Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access. | |
| Title | V-SOL GPON/EPON OLT Platform 2.03 Unauthenticated Configuration Download | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:23:32.107Z
Reserved: 2025-12-24T14:27:12.476Z
Link: CVE-2019-25239
No data.
Status : Deferred
Published: 2025-12-24T20:15:51.690
Modified: 2026-04-15T00:35:42.020
Link: CVE-2019-25239
No data.
OpenCVE Enrichment
No data.