vendor:
JT3500V
by:
LiquidWorm
8.8
CVSS
HIGH
Command Injection
78
CWE
Product Name: JT3500V
Affected Version From: 2.0.0B01
Affected Version To: 2.0.1B1064
Patch Exists: NO
Related CWE: N/A
CPE: h:kzbtech:jt3500v
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2021
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 – Command Injection (Authenticated)
JT3500V is a most advanced LTE-A Pro CAT12 indoor Wi-Fi & VoIP CPE product specially designed to enable quick and easy LTE fixed data service deployment for residential and SOHO customers. It provides high speed LAN, Wi-Fi and VoIP integrated services to end users who need both bandwidth and multi-media data service in residential homes or enterprises. The device has 2 Gigabit LAN ports, 1 RJ11 analog phone port, high performance 4x4 MIMO and CA capabilities, 802.11b/g/n/ac dual band Wi-Fi, advanced routing and firewall software for security. It provides an effective all-in-one solution to SOHO or residential customers. It can deliver up to 1Gbps max data throughput.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in system commands.