Critical severity9.8NVD Advisory· Published Nov 21, 2019· Updated Jun 17, 2026
CVE-2019-16340
CVE-2019-16340
Description
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:o:linksys:velop_whw0301_firmware:1.1.8.192419:*:*:*:*:*:*:*
- cpe:2.3:o:linksys:velop_whw0302_firmware:1.1.8.192419:*:*:*:*:*:*:*
- cpe:2.3:o:linksys:velop_whw0303_firmware:1.1.8.192419:*:*:*:*:*:*:*
- Belkin/Linksys Velopdescription
- Range: <=1.1.8.192419
Patches
Vulnerability mechanics
References
3- www.linksys.com/us/support-articlenvdPatchThird Party Advisory
- puzzor.github.io/Linksys-Velop-Authentication-bypassnvdExploitThird Party Advisory
- s3.amazonaws.com/downloads.linksys.com/support/assets/releasenotes/WHW03_A03_Velop_Customer_Release_Notes_1.1.9.195026.txtnvdThird Party Advisory
News mentions
0No linked articles in our index yet.