Description
V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.
Problem types
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5538.php
www.exploit-db.com/exploits/47435 (ExploitDB-47435)
www.vsolcn.com (V-SOL Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5538.php (Zero Science Lab Disclosure (ZSL-2019-5538))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.