CVE-2019-19885: Bender COM465DP Firmware
Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
Affected products
- Bender COM465DP Firmware: before 4.2.0 (fixed in 4.2.0)
- Bender COM465ID Firmware: before 4.2.0 (fixed in 4.2.0)
- Bender COM465IP Firmware: before 4.2.0 (fixed in 4.2.0)
- Bender CP700 Firmware: before 4.2.0 (fixed in 4.2.0)
- Bender CP907 Firmware: before 4.2.0 (fixed in 4.2.0)
- Bender CP915 Firmware: before 4.2.0 (fixed in 4.2.0)
Published 2020-10-16. Last modified 2026-06-17.