CVE detail
CVE-2019-19495 — CVE-2019-19495
Published 2020-01-08 · Modified 2026-06-17 · Vendor technicolor · Product tc7230_steb_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0429
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the cable modem to port forward the modem's internal TELNET server, allowing external access to a root shell.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References