PT-2021-9836 · Mofi Network · Mofi4500-4Gxelte

Published

2021-02-01

·

Updated

2021-02-04

·

CVE-2020-15832

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Mofi Network MOFI4500-4GXeLTE version 4.1.5-std
Description An issue was discovered in the poof.cgi script, which contains undocumented code allowing remote reboot of the device. An adversary with the private key, but not the root password, can exploit this to remotely reboot the device.
Recommendations For Mofi Network MOFI4500-4GXeLTE version 4.1.5-std, consider disabling the poof.cgi script as a temporary workaround until a patch is available. Restrict access to the private key to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-15832

Affected Products

Mofi4500-4Gxelte