Description
Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.
Published: 2026-04-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure via unauthenticated download of router backup file
Action: Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Across
Across dr-810
Vendors & Products Across
Across dr-810

Sun, 12 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
Description Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.
Title Across DR-810 ROM-0 Unauthenticated File Disclosure
First Time appeared Furunosystems
Furunosystems acera 810 Firmware
Weaknesses CWE-538
CPEs cpe:2.3:o:furunosystems:acera_810_firmware:rom-0:*:*:*:*:*:*:*
Vendors & Products Furunosystems
Furunosystems acera 810 Firmware
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Across Dr-810
Furunosystems Acera 810 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-13T18:16:20.733Z

Reserved: 2026-04-12T12:12:00.220Z

Link: CVE-2019-25706

cve-icon Vulnrichment

Updated: 2026-04-13T15:50:40.556Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-12T13:16:33.470

Modified: 2026-04-13T15:01:43.663

Link: CVE-2019-25706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T12:55:51Z

Weaknesses