CVE-2019-15065: A vulnerability was discovered in HiNet GPON firmware < I040GWR190731 that allows an attacker to read arbitrary files
Published Oct 17, 2019
·Updated
A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
Affected Software
2 affected components
HiNet GPON firmware<i040gwr190731
HiNet GPON
Event History
Oct 17, 2019
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-15065?
The severity of CVE-2019-15065 is critical, with a CVSS score of 9.3.
2
What type of attack is possible with CVE-2019-15065?
CVE-2019-15065 allows an attacker to read arbitrary files on devices running vulnerable HiNet GPON firmware.
3
How can I mitigate the risks associated with CVE-2019-15065?
Mitigation for CVE-2019-15065 involves updating the HiNet GPON firmware to a version that is not vulnerable.
4
Which firmware versions are affected by CVE-2019-15065?
CVE-2019-15065 affects HiNet GPON firmware versions earlier than I040GWR190731.
5
What is the attack vector for CVE-2019-15065?
The attack vector for CVE-2019-15065 is through a service hosted on port 6998.