Mofinetwork

Mofi4500-4gxelte Firmware

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 01.02.2021 02:15:15
  • Zuletzt bearbeitet 21.11.2024 05:06:17

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management interface.

  • EPSS 0.37%
  • Veröffentlicht 01.02.2021 02:15:15
  • Zuletzt bearbeitet 21.11.2024 05:06:17

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the priva...

  • EPSS 0.94%
  • Veröffentlicht 01.02.2021 02:15:15
  • Zuletzt bearbeitet 21.11.2024 05:06:17

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request can be sent to execute arbitrary commands as root.

  • EPSS 0.49%
  • Veröffentlicht 01.02.2021 02:15:14
  • Zuletzt bearbeitet 21.11.2024 05:02:01

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installatio...

  • EPSS 0.34%
  • Veröffentlicht 01.02.2021 02:15:14
  • Zuletzt bearbeitet 21.11.2024 05:02:01

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to th...

  • EPSS 0.32%
  • Veröffentlicht 01.02.2021 02:15:14
  • Zuletzt bearbeitet 21.11.2024 05:02:01

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.

  • EPSS 0.37%
  • Veröffentlicht 01.02.2021 02:15:14
  • Zuletzt bearbeitet 21.11.2024 05:06:16

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. An adversary with the private key (but not the root password) can remo...

  • EPSS 0.36%
  • Veröffentlicht 01.02.2021 02:15:14
  • Zuletzt bearbeitet 21.11.2024 05:06:16

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in a /rom location that cannot be...

  • EPSS 0.37%
  • Veröffentlicht 01.02.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:02:01

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.

  • EPSS 0.29%
  • Veröffentlicht 01.02.2021 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:01

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.