CVE-2020-15834
- EPSS 0.28%
- Veröffentlicht 01.02.2021 02:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:17
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management interface.
- EPSS 0.37%
- Veröffentlicht 01.02.2021 02:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:17
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the priva...
- EPSS 0.94%
- Veröffentlicht 01.02.2021 02:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:17
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request can be sent to execute arbitrary commands as root.
CVE-2020-13858
- EPSS 0.49%
- Veröffentlicht 01.02.2021 02:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installatio...
CVE-2020-13859
- EPSS 0.34%
- Veröffentlicht 01.02.2021 02:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to th...
CVE-2020-13860
- EPSS 0.32%
- Veröffentlicht 01.02.2021 02:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.
CVE-2020-15832
- EPSS 0.37%
- Veröffentlicht 01.02.2021 02:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:16
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. An adversary with the private key (but not the root password) can remo...
- EPSS 0.36%
- Veröffentlicht 01.02.2021 02:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:16
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in a /rom location that cannot be...
CVE-2020-13857
- EPSS 0.37%
- Veröffentlicht 01.02.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:02:01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.
CVE-2020-13856
- EPSS 0.29%
- Veröffentlicht 01.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.