Vulnerability record · CVE-2019-16313 · published 14 September 2019
CVE-2019-16313: ifw8 Router ROM credential disclosure in usermanager.htm source
IIfw8 · Fr6 Firmware
ifw8 Router ROM v4.31 exposes credentials in the HTML source of action/usermanager.htm. Anyone who can reach that page can read the credentials directly from the response, so the flaw undermines the router's authentication model. The record lists firmware products but no specific affected versions beyond v4.31.
Description
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityRemote unauthenticated credential disclosure with public exploit references and very high EPSS, though not in KEV and requiring network reach to the management page.
What it is
ifw8 Router ROM v4.31 exposes credentials in the HTML source of action/usermanager.htm. Anyone who can reach that page can read the credentials directly from the response, so the flaw undermines the router's authentication model. The record lists firmware products but no specific affected versions beyond v4.31.
Impact
An attacker obtains valid credentials for the router, enabling authenticated access and further configuration or network compromise. The direct impact is credential theft; the CVSS vector rates confidentiality as high with no integrity or availability effect.
Attack surface
Reachable over the network via HTTP to the action/usermanager.htm endpoint. The CVSS vector shows no privileges and no user interaction required, so the page can be fetched directly by an unauthenticated remote client.
Exploitation
Not listed in CISA KEV, but EPSS is 0.46109 (98.75th percentile), indicating high predicted exploitation activity. Both references are tagged Exploit, so public exploit material exists.
What to do
- Apply the vendor firmware update that removes credentials from the usermanager.htm source; if no fix is available, isolate or replace affected devices.
- Restrict management interface access to a trusted management VLAN or VPN and block internet exposure of the router web UI.
- Change default and any exposed credentials on affected devices, and rotate credentials that may have been read from the page.
- Monitor vendor advisories for the listed FR5, FR5-E, FR6, FR6-S and FR8 firmware products for a patched release.
Detection
- Search web/proxy logs for requests to action/usermanager.htm, especially from unexpected or external source addresses.
- Inspect HTTP response bodies for credential-like strings returned from usermanager.htm.
- Alert on management-interface access from outside the trusted management network.
- Review router authentication logs for logins using credentials that appear in exposed page content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.iwantacve.cn/index.php/archives/311/ | ExploitThird Party Advisory |
| http://www.iwantacve.cn/index.php/archives/311/ | ExploitThird Party Advisory |
Track CVE-2019-16313 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16313), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.