PT-2025-53336 · Devolo · Devolo Dlan 500 Av Wireless+

Published

2025-12-24

·

Updated

2025-12-24

·

CVE-2019-25250

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Devolo dLAN 500 AV Wireless+ version 3.1.0-1
Description The software contains a cross-site request forgery issue that enables attackers to perform administrative actions without proper request validation. Attackers can create malicious web pages that initiate unauthorized configuration changes by exploiting predictable URL actions when a logged-in user visits the site.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-25250

Affected Products

Devolo Dlan 500 Av Wireless+