CVE-2019-25706

HIGH

Across DR-810 ROM-0 Unauthenticated File Disclosure

Title source: cna
STIX 2.1

Description

Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.

Exploits (1)

exploitdb WORKING POC
by SajjadBnd · textwebappshardware
https://www.exploit-db.com/exploits/46132

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-538
Status published
Products (1)
Across/DR-810 ROM-0
Published Apr 12, 2026
Tracked Since Apr 12, 2026