AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-7311

HIGH · CVSS 7.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-06 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.

CVE
CVE-2019-7311
Severity
HIGH
CVSS
7.8
EPSS
0.18%

Original NVD Description

An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a local attacker, and usable to gain administrative access to the victim's router. The admin password is stored in base64 cleartext in an "admin-auth" cookie. An attacker sniffing the network at the time of login could acquire the router's admin password. Alternatively, gaining physical access to the victim's computer soon after an administrative login could result in compromise.

Related CVEs

Other vulnerabilities affecting the same vendor(s)