CVE-2019-17216: Vzug Combi-Stream Mslq Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort.

Affected products

  • Vzug Combi-Stream Mslq Firmware: before ethernet_r07 (fixed in ethernet_r07); before wlan_r05 (fixed in wlan_r05)

Published 2019-10-06. Last modified 2026-06-17.