VYPR

AC2400

by Comba Telecom

CVEs (1)

  • CVE-2019-15654HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.02

    Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doesn't require any authentication and will lead to saving the DBconfig.cfg file. At the end of the…