PT-2026-1671 · Devolo · Devolo Dlan Cockpit
Stefan Petrushevski
·
Published
2026-01-07
·
Updated
2026-01-08
·
CVE-2019-25231
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
devolo dLAN Cockpit version 4.3.1
Description
The software contains an unquoted service path issue in the 'DevoloNetworkService'. This allows local, non-privileged users to potentially execute arbitrary code. Exploitation involves leveraging the insecure service path configuration by placing malicious code in the system root path, which then executes with elevated privileges during application startup or system reboot.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devolo Dlan Cockpit