PT-2019-18612 · Jio · Jiofi 4G M2S

Vikas Chaudhary

·

Publicado

2019-03-20

·

Atualizado

2020-08-24

·

CVE-2019-7439

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JioFi 4G M2S version 1.0.2
Description The issue affects the cgi-bin/qcmap web cgi endpoint on the device, allowing a denial of service (DoS) that causes the device to hang when the mask POST parameter is exploited.
Recommendations For JioFi 4G M2S version 1.0.2, as a temporary workaround, consider restricting access to the cgi-bin/qcmap web cgi endpoint to minimize the risk of exploitation. Avoid using the mask parameter in the affected endpoint until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-7439

Produtos afetados

Jiofi 4G M2S