← Vulnerability feed

Vulnerability record · CVE-2019-16313 · published 14 September 2019

CVE-2019-16313: ifw8 Router ROM credential disclosure in usermanager.htm source

IIfw8 · Fr6 Firmware

ifw8 Router ROM v4.31 exposes credentials in the HTML source of action/usermanager.htm. Anyone who can reach that page can read the credentials directly from the response, so the flaw undermines the router's authentication model. The record lists firmware products but no specific affected versions beyond v4.31.

7.5 CVSS 3.1 High EPSS 46% · top 1.2% CWE-798 · Hard-coded credentials
7.5CVSS 3.1 base score, v2 5.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated credential disclosure with public exploit references and very high EPSS, though not in KEV and requiring network reach to the management page.

What it is

ifw8 Router ROM v4.31 exposes credentials in the HTML source of action/usermanager.htm. Anyone who can reach that page can read the credentials directly from the response, so the flaw undermines the router's authentication model. The record lists firmware products but no specific affected versions beyond v4.31.

Impact

An attacker obtains valid credentials for the router, enabling authenticated access and further configuration or network compromise. The direct impact is credential theft; the CVSS vector rates confidentiality as high with no integrity or availability effect.

Attack surface

Reachable over the network via HTTP to the action/usermanager.htm endpoint. The CVSS vector shows no privileges and no user interaction required, so the page can be fetched directly by an unauthenticated remote client.

Exploitation

Not listed in CISA KEV, but EPSS is 0.46109 (98.75th percentile), indicating high predicted exploitation activity. Both references are tagged Exploit, so public exploit material exists.

What to do

  • Apply the vendor firmware update that removes credentials from the usermanager.htm source; if no fix is available, isolate or replace affected devices.
  • Restrict management interface access to a trusted management VLAN or VPN and block internet exposure of the router web UI.
  • Change default and any exposed credentials on affected devices, and rotate credentials that may have been read from the page.
  • Monitor vendor advisories for the listed FR5, FR5-E, FR6, FR6-S and FR8 firmware products for a patched release.

Detection

  • Search web/proxy logs for requests to action/usermanager.htm, especially from unexpected or external source addresses.
  • Inspect HTTP response bodies for credential-like strings returned from usermanager.htm.
  • Alert on management-interface access from outside the trusted management network.
  • Review router authentication logs for logins using credentials that appear in exposed page content.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.iwantacve.cn/index.php/archives/311/ ExploitThird Party Advisory
http://www.iwantacve.cn/index.php/archives/311/ ExploitThird Party Advisory

Track CVE-2019-16313 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed9.8CVE-2025-30406Gladinet CentreStack hardcoded machineKey deserialization RCEGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) uses a hardcoded machineKey in the portal's web.config, allowing deserializ…KEVEPSS 94%analysed9.8CVE-2024-20439Cisco Smart Licensing Utility hard-coded admin credential allows remote loginCisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who…KEVEPSS 97%analysed8.1CVE-2021-44207Acclaim USAHERDS hard-coded credentials allow remote compromiseAcclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the …KEVEPSS 18%analysed9.1CVE-2024-28987SolarWinds Web Help Desk hardcoded credential flawSolarWinds Web Help Desk contains a hardcoded credential vulnerability (CWE-798) that lets a remote, unauthenticated attacker reach internal function…KEVEPSS 93%analysed9.8CVE-2024-3272D-Link NAS Devices Hard-Coded Credentials in nas_sharing.cgiD-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'u…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2019-16313), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.