Executive brief
The Across DR-810, a SIM card modem and router, contains a security flaw that allows anyone on the internet to download its configuration backup file without a password. This file contains sensitive information, including the router's administrative password and other configuration details. An attacker who obtains this file can gain full control over the device, potentially intercepting internet traffic or modifying network settings.
Technical details
The Across DR-810 router is vulnerable to an unauthenticated file disclosure vulnerability affecting the 'rom-0' endpoint. The device, which utilizes RomPager 4.07, fails to implement proper access controls on the configuration backup file. A remote, unauthenticated attacker can retrieve this file by sending a direct HTTP GET request to the /rom-0 URI. Once downloaded, the file can be decompressed to reveal plaintext administrative passwords and other sensitive configuration data, leading to full device compromise. This is a known issue common to several legacy RomPager-based network devices.
Affected products
- Across DR-810 All versions using RomPager 4.07
Timeline
- 2019-01-11: disclosed: Initial discovery by researcher SajjadBnd
- 2019-01-14: other: Exploit published on Exploit-DB
- 2026-04-12: advisory: CVE published/updated via VulnCheck and NVD