CVE-2019-25298

html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted payloads.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lolypop55:html5_snmp:-:*:*:*:*:*:*:*

History

24 Feb 2026, 21:14

Type Values Removed Values Added
First Time Lolypop55 html5 Snmp
Lolypop55
References () https://github.com/lolypop55/html5_snmp - () https://github.com/lolypop55/html5_snmp - Product
References () https://www.exploit-db.com/exploits/47588 - () https://www.exploit-db.com/exploits/47588 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/htmlsnmp-routerid-sql-injection - () https://www.vulncheck.com/advisories/htmlsnmp-routerid-sql-injection - Broken Link
CPE cpe:2.3:a:lolypop55:html5_snmp:-:*:*:*:*:*:*:*

06 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 17:16

Updated : 2026-02-24 21:14


NVD link : CVE-2019-25298

Mitre link : CVE-2019-25298

CVE.ORG link : CVE-2019-25298


JSON object : View

Products Affected

lolypop55

  • html5_snmp
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')