V-SOL GPON/EPON OLT Unauthenticated Information Disclosure Vulnerability
Vulnerability
An unauthenticated information disclosure vulnerability has been identified in V-SOL GPON/EPON OLT Platform version 2.03. This vulnerability allows attackers to download sensitive configuration files by sending HTTP GET requests to the usrcfg.conf endpoint. The exposed configuration data could facilitate authentication bypass and unauthorized system access.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive configuration information, potentially allowing for authentication bypass and full system access.
Reproduction
The vulnerability can be reproduced by sending an HTTP GET request to the usrcfg.conf endpoint on the OLT device. This can be done using a tool like curl.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
