6.4
CVSSv2

CVE-2019-16340

Published: 21/11/2019 Updated: 21/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Belkin Linksys Velop 1.1.8.192419 devices allows remote malicious users to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linksys velop_whw0303_firmware 1.1.8.192419

linksys velop_whw0302_firmware 1.1.8.192419

linksys velop_whw0301_firmware 1.1.8.192419