An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely authenticate to the management interface as root.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMofinetwork Mofi4500 4gxelte
HWMofinetworkall versionsMofinetwork Mofi4500 4gxelte Firmware
OSMofinetwork4.1.5-std
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2020-13859CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia przez ukryte konto w routerze MOFI4500-4GXeLTE
CVE-2020-15833CRITICAL9.8PL ✓same product
Hardkodowany klucz publiczny SSH umożliwiający dostęp root w MOFI4500-4GXeLTE
CVE-2020-13858CRITICAL9.8PL ✓same product
Ukryte konta administratora w routerach Mofi Network MOFI4500-4GXeLTE
CVE-2020-15836CRITICAL9.8PL ✓same product
Command injection w funkcji uwierzytelniania routera MOFI4500-4GXeLTE
CVE-2020-15834HIGH7.5same product
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is e...