HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2019-25706 — Across DR-810 contains an unauthenticated file disclosure vulnerability that all...

·Source: NIST NVD

Updated:

Executive Summary

Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.

Analysis

Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data. CVSS Score: 7.5. Published: 2026-04-12T13:16:33.470.

Indicators of Compromise (1)

CVE (1)
CVE-2019-25706
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats