CVE-2019-15654
Description
Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doesn't require any authentication and will lead to saving the DBconfig.cfg file. At the end of the file, the login information is stored in cleartext.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Comba AC2400 devices expose cleartext login credentials via an unauthenticated download of DBconfig.cfg through /09/business/upgrade/upcfgAction.php.
Vulnerability
Comba AC2400 devices (firmware versions prior to an unknown patched release) contain an information disclosure vulnerability in the web management server. A specially crafted request to /09/business/upgrade/upcfgAction.php?download=true downloads the DBconfig.cfg file without requiring any authentication. The cleartext login credentials are stored at the end of this file. [1]
Exploitation
An attacker with network access to the device's web management interface can send an HTTP GET request to the vulnerable endpoint. No authentication or prior knowledge is required. The attacker simply visits the URL http://<device_ip>/09/business/upgrade/upcfgAction.php?download=true and receives the full database configuration file, which includes plaintext credentials that are typically the device admin login. [1]
Impact
Successful exploitation allows an unauthenticated attacker to obtain the device's administrative login credentials in cleartext. This leads to full compromise of the Comba AC2400 device, including access to configuration settings, ability to change parameters, and potential use as a pivot point within the network. [1]
Mitigation
Comba has not publicly disclosed a fixed firmware version [2]. Users are advised to restrict network access to the web management interface to trusted hosts only, place the device behind a firewall, and monitor for unauthorized access. As of this writing, no patch is available, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Comba/AC2400 devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.comba-telecom.com/en/newsmitrex_refsource_MISC
- www.trustwave.com/en-us/resources/security-resources/security-advisories/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.