CVE detail
CVE-2019-16651 — CVE-2019-16651
Published 2021-09-20 · Modified 2026-06-17 · Vendor virginmedia · Product super_hub_3_firmware · Source nvd
MEDIUM
severity
CVSS-derived band
0.0115
EPSS probability
exploitation probability, 30d
64.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN implementations, this would decloak them).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References