VYPR

AC2400

by Comba Telecom

CVEs (1)

  • CVE-2019-15654Mar 19, 2020
    risk 0.00cvss epss 0.00

    Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doesn't require any authentication and will lead to saving the DBconfig.cfg file. At the end of the…