An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. An adversary with the private key (but not the root password) can remotely reboot the device.
References
Link | Resource |
---|---|
https://mofinetwork.com/index.php?main_page=page&id=14 | Patch Vendor Advisory |
https://www.criticalstart.com/critical-vulnerabilities-discovered-in-mofi-routers/ | Technical Description Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-01T01:36:34
Updated: 2021-02-01T01:36:34
Reserved: 2020-07-19T00:00:00
Link: CVE-2020-15832
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-02-01T02:15:14.927
Modified: 2021-02-04T15:36:48.533
Link: CVE-2020-15832
JSON object: View
Redhat Information
No data.
CWE