An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://mofinetwork.com/index.php?main_page=page&id=14 | patch vendor advisory |
https://www.criticalstart.com/critical-vulnerabilities-discovered-in-mofi-routers/ | third party advisory technical description |