CVE-2019-25227
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-26

Last updated on: 2025-11-26

Assigner: VulnCheck

Description
Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/system_config_file management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without requiring authentication or authorization. The exposed configuration may include administrative credentials, wireless keys, and other sensitive settings, enabling an unauthenticated attacker to obtain information that can facilitate further compromise of the device or network.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-26
Last Modified
2025-11-26
Generated
2026-05-07
AI Q&A
2025-11-27
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
tellion hn-2204ap *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Tellion HN-2204AP routers where the /cgi-bin/system_config_file management endpoint allows anyone to remotely download a compressed configuration archive without needing to log in or have any authorization. This archive can contain sensitive information such as administrative credentials and wireless keys, which can be used by an attacker to further compromise the device or the network.


How can this vulnerability impact me? :

An attacker can exploit this vulnerability to obtain sensitive configuration data from the router, including administrative credentials and wireless keys. This can lead to unauthorized access to the device and the network it manages, potentially allowing the attacker to control the router, intercept network traffic, or launch further attacks within the network.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart