vendor:
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE
by:
LiquidWorm
5.5
CVSS
MEDIUM
Factory Reset (Unauthenticated)
259
CWE
Product Name: KZTech/JatonTec/Neotel JT3500V 4G LTE CPE
Affected Version From: JT3500V 2.0.1B1064
Affected Version To: JT3120R 2.0.0B01
Patch Exists: NO
Related CWE:
CPE: o:kz_broadband_technologies:ltd:kz3220m_firmware:2.0.0b04
Platforms Tested:
2021
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 – Factory Reset (Unauthenticated)
The KZTech/JatonTec/Neotel JT3500V 4G LTE CPE version 2.0.1 is affected by an unauthenticated factory reset vulnerability. This allows an attacker to reset the device to its factory default settings without authentication, potentially giving them unauthorized access to the device and its services.
Mitigation:
To mitigate this vulnerability, users should ensure that the device is running the latest firmware version. Additionally, it is recommended to change the default credentials and disable remote management access to the device.