CVE-2019-25706
Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.53%
- CWE
- CWE-538
- Published
- 2026-04-12
- Last modified
- 2026-04-13
Affected products
- Across DR-810
Weakness type
Related vulnerabilities
- CVE-2026-80175 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-69507 — Microsoft Windows Search Component Information Disclosure Vulnerability
- CVE-2026-67361 — Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
- CVE-2026-19229 — SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
- CVE-2026-12762 — Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
- CVE-2026-15574 — Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default
- CVE-2025-36372 — IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
- CVE-2026-50099 — Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directory