Verizon

Lvskihp Outdoorunit Firmware

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.12%
  • Veröffentlicht 14.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:13

On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmware update for the device. /lib/functions/wnc_jsonsh/wnc_crtc_fw.sh has no cryptographic validation of the image...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 14.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:14

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static certificate for access control. This certificate is embedded in the firmware, and is identical across the...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 14.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:14

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a means of provisioning a firmware update for the device via crtc_fw_upgrade or crtcfwimage. The URL provided is n...

Exploit
  • EPSS 4.43%
  • Veröffentlicht 14.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:14

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inject shell me...

Exploit
  • EPSS 4.39%
  • Veröffentlicht 14.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:14

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters i...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:14

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generated via a binary included in the...