PT-2026-1671 · Devolo · Devolo Dlan Cockpit
Stefan Petrushevski
·
Publicado
2026-01-07
·
Atualizado
2026-01-08
·
CVE-2019-25231
CVSS v3.1
8.4
Alta
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
devolo dLAN Cockpit version 4.3.1
Description
The software contains an unquoted service path issue in the 'DevoloNetworkService'. This allows local, non-privileged users to potentially execute arbitrary code. Exploitation involves leveraging the insecure service path configuration by placing malicious code in the system root path, which then executes with elevated privileges during application startup or system reboot.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Devolo Dlan Cockpit