Description
V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.
Problem types
Files or Directories Accessible to External Parties
Product status
V2.03.54R
V2.03.52R
V2.03.49
V2.03.47
V2.03.40
V2.03.26
V2.03.24
V1.8.6
V1.4
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5534.php
www.exploit-db.com/exploits/47433
www.exploit-db.com/exploits/47433 (ExploitDB-47433)
www.vsolcn.com (V-SOL Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5534.php (Zero Science Lab Disclosure (ZSL-2019-5534))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.