KZTech/JatonTec/Neotel JT3500V 4G...

- AV AC AU C I A
发布: 2021-03-19
修订: 2025-04-13

KZTech/JatonTec/Neotel JT3500V 4G LTE CPE version 2.0.1 suffers from a privilege escalation vulnerability. The non-privileged default user (user:user123) can elevate his/her privileges by sending a HTTP GET request to the configuration export endpoint and disclose the admin password. Once authenticated as admin, an attacker will be granted access to the additional and privileged pages.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息