vendor:
JT3500V 4G LTE CPE
by:
LiquidWorm
7.5
CVSS
HIGH
Config Download (Unauthenticated)
284
CWE
Product Name: JT3500V 4G LTE CPE
Affected Version From: JT3500V 2.0.1B1064
Affected Version To: JT3120R 2.0.0B01
Patch Exists: NO
Related CWE:
CPE: o:kz_broadband_technologies:kztech_jatontec_neotel_jt3500v_firmware:2.0.1
Platforms Tested:
2021
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 – Config Download (Unauthenticated)
The KZTech/JatonTec/Neotel JT3500V 4G LTE CPE version 2.0.1 is vulnerable to an unauthenticated configuration download exploit. This vulnerability allows an attacker to download the device's configuration without authentication, potentially exposing sensitive information.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to restrict network access to the device and implement strong authentication mechanisms.