Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2020-13858
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.
0
Attacker Value
Unknown
CVE-2020-13857
Disclosure Date: February 01, 2021 (last updated November 28, 2024)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.
0
Attacker Value
Unknown
CVE-2020-13860
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.
0
Attacker Value
Unknown
CVE-2020-13859
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.
0
Attacker Value
Unknown
CVE-2020-13856
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.
0