PT-2021-9836 · Mofi Network · Mofi4500-4Gxelte
Published
2021-02-01
·
Updated
2021-02-04
·
CVE-2020-15832
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Mofi Network MOFI4500-4GXeLTE version 4.1.5-std
Description
An issue was discovered in the poof.cgi script, which contains undocumented code allowing remote reboot of the device. An adversary with the private key, but not the root password, can exploit this to remotely reboot the device.
Recommendations
For Mofi Network MOFI4500-4GXeLTE version 4.1.5-std, consider disabling the poof.cgi script as a temporary workaround until a patch is available. Restrict access to the private key to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mofi4500-4Gxelte