Back

HIGH

Across DR-810 ROM-0 Unauthenticated File Disclosure

Published Apr 12, 2026

Description

Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 12, 2026
Updated Apr 13, 2026
Reserved Apr 12, 2026
CISA Vulnrichment
Updated Apr 13, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Apr 12, 2026
Updated Apr 13, 2026
Exploited since n/a
EUVD-2019-20136