CVE-2019-15911
Estado: ModificadaCrítica (9.8)—
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-15911",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-12-20T17:15:11.347",
"references": [
{
"url": "https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15911.md",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15911.md",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages."
},
{
"lang": "es",
"value": "Se descubrió un problema en los dispositivos ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 que usan ZigBee PRO. Debido al transporte inseguro de claves en la comunicación de ZigBee, los atacantes pueden obtener información confidencial, provocar múltiples ataques de denegación de servicio, hacerse cargo de dispositivos domésticos inteligentes y manipular los mensajes."
}
],
"lastModified": "2026-06-17T02:21:18.700",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:hg100_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C6475F7-122A-4D65-8191-9B4A537FB1DB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:hg100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DFEFB004-6477-408B-A114-8ABCA8AC8D19"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:mw100_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B477A45-4E68-46B2-80F5-30B0F230EB25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:mw100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6BA0BD66-6D94-43EF-BF10-8876E1B57EDD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:ws-101_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2C3A04B-F863-4AB3-A6CA-692740E4F54C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:ws-101:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ED316BAF-834B-4DE0-9F57-58DCF2A2B173"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:ts-101_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F1C7AC1-C698-4F5B-A556-327A66A0A8E3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:ts-101:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FAF8B970-AB76-47D7-B43A-C802643A0646"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:as-101_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6394F3BE-8032-40A5-B534-9FF62709BEC7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:as-101:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D3950E49-F5A9-412B-94AB-258A87BBD965"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:ms-101_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70CAEAA8-DCB8-4154-A9D6-F4EFC11C2D4A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:ms-101:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2839A31C-D770-44D8-943C-160AEAD2701E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:dl-101_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4434E4C0-D531-4485-B20F-1513B3D0E902"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:dl-101:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1875F5A1-2C3A-494E-B657-1730B8415735"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}