CVE-2019-19941: Swisscom Centro Grande Firmware

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.

Affected products

  • Swisscom Centro Grande Firmware: before 6.14.06 (fixed in 6.14.06)

Published 2020-03-16. Last modified 2026-06-17.