CVE-2019-25237
CRITICALV-SOL GPON/EPON OLT Platform v2.03 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25237. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in V-SOL GPON/EPON OLT Platform by sending a crafted HTTP POST request to modify the user role to admin (value '1'). The PoC includes an HTML form that automates the attack.
Description
V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in V-SOL GPON/EPON OLT Platform by sending a crafted HTTP POST request to modify the user role to admin (value '1'). The PoC includes an HTML form that automates the attack.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H