CVE-2019-25282 Details
Description
V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipulate the 'parent' GET parameter. Attackers can craft malicious links that redirect logged-in users to arbitrary websites by exploiting improper input validation in the redirect mechanism.
An open redirect vulnerability has been identified in V-SOL GPON/EPON OLT Platform version 2.03. This vulnerability allows attackers to manipulate the 'parent' GET parameter in the 'bindProfile.html' script, leading to unauthorized redirection of logged-in users to arbitrary websites. The issue arises from inadequate input validation in the redirection mechanism.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 8, 2026CISA-ADP
Assessed Jan 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cxsecurity.com/issue/WLB-2019090193 | [email protected] | ExploitTechnical Description |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/167772 | [email protected] | Advisory |
| https://packetstormsecurity.com/files/154628 | [email protected] | Exploit |
| https://www.vsolcn.com/ | [email protected] | Vendor |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5535.php | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Guangzhou V-SOLUTION V-SOL GPON/EPON OLT Platform | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2026 | New CVE Received | [email protected] |
Volerion