Vulnerability Details CVE-2020-13858
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-13858
-
cpe:2.3:h:mofinetwork:mofi4500-4gxelte:-
-
cpe:2.3:o:mofinetwork:mofi4500-4gxelte_firmware:3.6.1-std
-
cpe:2.3:o:mofinetwork:mofi4500-4gxelte_firmware:4.0.8-std