nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25250 CVE-2019-25250
MEDIUM
Devolo dLAN 500 AV Wireless+ 3.1.0-1 Cross-Site Request Forgery
Record summary
CVE-2019-25250 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a logged-in user visits the site.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dLAN 550 duo+ Starter KitBrowse devolo AG / dLAN 550 duo+ Starter Kit | CVE List | 500 AV Wireless+ 3.1.0-1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBdevolo dLAN 550 duo+ Starter Kit - Cross-Site Request ForgeryExploitDB exploitby smNot analyzed1 file
References
4Official Product Homepageproduct
https://www.devolo.com/ ExploitDB-46324exploit
https://www.exploit-db.com/exploits/46324 Zero Science Lab Disclosure (ZSL-2019-5507)Third-party advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5507.php