Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_config management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without requiring authentication or authorization. The exposed configuration may include administrative credentials and other sensitive settings, enabling an unauthenticated attacker to obtain information that can facilitate further compromise of the device or network.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dongyoung
Dongyoung dm-ap240t/w Wireless Access Point |
|
| Vendors & Products |
Dongyoung
Dongyoung dm-ap240t/w Wireless Access Point |
Wed, 26 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_config management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without requiring authentication or authorization. The exposed configuration may include administrative credentials and other sensitive settings, enabling an unauthenticated attacker to obtain information that can facilitate further compromise of the device or network. | |
| Title | Dongyoung Media DM-AP240T/W Unauthenticated Configuration Disclosure | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-26T22:14:37.744Z
Reserved: 2025-11-26T15:33:00.768Z
Link: CVE-2019-25226
No data.
Status : Received
Published: 2025-11-26T23:15:45.857
Modified: 2025-11-26T23:15:45.857
Link: CVE-2019-25226
No data.