4.3
CVSSv2

CVE-2019-7440

Published: 21/03/2019 Updated: 02/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jio jiofi_4g_m2s_firmware 1.0.2

Exploits

# Exploit Title: JioFi 4G M2S 102 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi) # Exploit Author: Vikas Chaudhary # Date: 21-01-2019 # Vendor Homepage: wwwjiocom/ # Hardware Link: wwwamazonin/JioFi-Hotspot-M2S-Portable-Dev ...
JioFi 4G M2S version 102 suffers from a cross site request forgery vulnerability ...