HIGH
devolo dLAN Cockpit 4.3.1 Unquoted Service Path Privilege Escalation
Published Jan 7, 2026
8.5
HIGHCVSS 4.0
EPSS 0.15%
Description
devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows local non-privileged users to potentially execute arbitrary code. Attackers can exploit the insecure service path configuration by inserting malicious code in the system root path to execute with elevated privileges during application startup or system reboot.
Affected products
-
- Version 4.3.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| devolo AG | devolo dLAN Cockpit | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://cxsecurity.com/issue/WLB-2019020037 third-party-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1615 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/156594 vdb-entry
- https://packetstormsecurity.com/files/151525 exploit
- https://www.devolo.global/ product
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5506.php third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://cxsecurity.com/issue/WLB-2019020037 | third-party-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1615 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/156594 | vdb-entry | |
| https://packetstormsecurity.com/files/151525 | exploit | |
| https://www.devolo.global/ | product | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5506.php | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 7, 2026
Updated Jan 8, 2026
Reserved Dec 17, 2025
Link CVE-2019-25231
CISA Vulnrichment
Updated Jan 8, 2026
ENISA EUVD
EUVD-2026-1615 Assigner VulnCheck
Published Jan 7, 2026
Updated Jan 8, 2026
Exploited since n/a
Link EUVD-2026-1615