CVE-2019-16651: Virginmedia Super Hub 3 Firmware

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN implementations, this would decloak them).

Affected products

  • Virginmedia Super Hub 3 Firmware: affected versions not specified

Published 2021-09-20. Last modified 2026-06-17.