Stefan Petrushevski aka sm

3 exploits Active since Dec 2025
CVE-2019-25250 EXPLOITDB MEDIUM text WORKING POC
Devolo dLAN 500 AV Wireless+ <3.1.0-1 - CSRF
Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a logged-in user visits the site.
CVSS 5.3
CVE-2019-25249 EXPLOITDB CRITICAL text WORKING POC
devolo dLAN 500 AV Wireless+ <3.1.0-1 - Auth Bypass
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
CVSS 9.8
EIP-2026-116601 EXPLOITDB python WORKING POC
Xitami Web Server 5.0a0 - Denial of Service