{"cve":"CVE-2019-3914","epss":{"score":0.29885},"mitre":{"cpes":[],"created":"2019-04-11T13:53:37+00:00","description":"Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2019/3xxx/CVE-2019-3914.json","references":["https://www.tenable.com/security/research/tra-2019-17"],"title":null,"updated":"2024-08-04T19:26:27.491000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:h:verizon:fios_quantum_gateway_g1100:-:*:*:*:*:*:*:*","cpe:2.3:o:verizon:fios_quantum_gateway_g1100_firmware:02.01.00.05:*:*:*:*:*:*:*"],"created":"2019-04-11T14:29:00.233000+00:00","description":"Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.","metrics":{"cvssV2_0":{"score":9.0,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C"},"cvssV3_0":{"score":7.2,"vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"cvssV3_1":{},"cvssV4_0":{}},"nvd_repo_path":"2019/CVE-2019-3914.json","references":["https://www.tenable.com/security/research/tra-2019-17"],"title":null,"updated":"2026-06-17T02:35:51.317000+00:00","vendors":["verizon","verizon$PRODUCT$fios_quantum_gateway_g1100","verizon$PRODUCT$fios_quantum_gateway_g1100_firmware"],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.27902},"old":{"score":0.28882}}}},"type":"metrics"}],"id":"350f5cc3-028b-4cf5-8fd3-5e71b9ae3fd9"}],"cpes":{"data":["cpe:2.3:h:verizon:fios_quantum_gateway_g1100:-:*:*:*:*:*:*:*","cpe:2.3:o:verizon:fios_quantum_gateway_g1100_firmware:02.01.00.05:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2019-04-11T13:53:37+00:00","provider":"mitre"},"description":{"data":"Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":9.0,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C"},"provider":"nvd"},"cvssV3_0":{"data":{"score":7.2,"vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.29885},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.tenable.com/security/research/tra-2019-17"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2024-11-21T04:42:51.260000+00:00","provider":"nvd"},"vendors":{"data":["verizon","verizon$PRODUCT$fios_quantum_gateway_g1100","verizon$PRODUCT$fios_quantum_gateway_g1100_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-78"],"providers":["nvd"]}}}