vendor:
JT3500V
by:
LiquidWorm
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: JT3500V
Affected Version From: 2.0.0B01
Affected Version To: 2.0.1B1064
Patch Exists: YES
Related CWE: CVE-2021-25212
CPE: h:kzbtech:jt3500v
Other Scripts:
N/A
Platforms Tested: None
2021
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 – Authentication Bypass
A vulnerability in KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 allows an unauthenticated attacker to bypass authentication and gain access to the device. This vulnerability exists due to the lack of proper authentication checks when handling requests to the web interface. An attacker can exploit this vulnerability by sending a specially crafted request to the web interface. This will allow the attacker to bypass authentication and gain access to the device.
Mitigation:
Upgrade to the latest version of the firmware.