Mofinetwork
Mofinetwork Mofi4500-4gxelte Firmware: vulnerabilidades y CVE
Mofinetwork Mofi4500-4gxelte Firmware tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-15836 | Crítica (9.8) | 2.2% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request can be sent to execute… |
| CVE-2020-15835 | Crítica (9.8) | 1.7% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root… |
| CVE-2020-15834 | Alta (7.5) | 1.1% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management… |
| CVE-2020-15833 | Crítica (9.8) | 1.6% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in… |
| CVE-2020-15832 | Alta (7.5) | 1.1% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. An adversary with the private key (but… |
| CVE-2020-13860 | Alta (7.5) | 1.1% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password. |
| CVE-2020-13859 | Crítica (9.8) | 1.2% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system… |
| CVE-2020-13858 | Crítica (9.8) | 1.4% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password… |
| CVE-2020-13857 | Alta (7.5) | 1.1% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request. |
| CVE-2020-13856 | Alta (7.5) | 1.2% | — | 1 feb 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password… |