nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25249 CVE-2019-25249
HIGH
devolo dLAN 500 AV Wireless+ 3.1.0-1 Remote Code Execution via htmlmgr
Record summary
CVE-2019-25249 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dLAN 550 duo+ Starter KitBrowse devolo AG / dLAN 550 duo+ Starter Kit | CVE List | 500 AV Wireless+ 3.1.0-1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBdevolo dLAN 550 duo+ Starter Kit - Remote Code ExecutionExploitDB exploitby smNot analyzed1 file
References
4Official Vendor Homepageproduct
https://www.devolo.com/ ExploitDB-46325exploit
https://www.exploit-db.com/exploits/46325 Zero Science Lab Disclosure (ZSL-2019-5508)Third-party advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5508.php