PT-2019-18612 · Jio · Jiofi 4G M2S
Vikas Chaudhary
·
Published
2019-03-20
·
Updated
2020-08-24
·
CVE-2019-7439
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JioFi 4G M2S version 1.0.2
Description
The issue affects the cgi-bin/qcmap web cgi endpoint on the device, allowing a denial of service (DoS) that causes the device to hang when the
mask POST parameter is exploited.Recommendations
For JioFi 4G M2S version 1.0.2, as a temporary workaround, consider restricting access to the cgi-bin/qcmap web cgi endpoint to minimize the risk of exploitation. Avoid using the
mask parameter in the affected endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jiofi 4G M2S