Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 12 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
Description Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.
Title Across DR-810 ROM-0 Unauthenticated File Disclosure
First Time appeared Furunosystems
Furunosystems acera 810 Firmware
Weaknesses CWE-538
CPEs cpe:2.3:o:furunosystems:acera_810_firmware:rom-0:*:*:*:*:*:*:*
Vendors & Products Furunosystems
Furunosystems acera 810 Firmware
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-12T12:28:52.102Z

Reserved: 2026-04-12T12:12:00.220Z

Link: CVE-2019-25706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-12T13:16:33.470

Modified: 2026-04-12T13:16:33.470

Link: CVE-2019-25706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses