go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

A remote command execution vulnerability was discovered in HiNet GPON firmware < I040GWR190731 port 3097

TVN ID TVN-201908005
CVE ID CVE-2019-13411
Affected Products GPON firmware version < I040GWR190731
Description An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097.
CVSS 3.0 Base score 10.0.
CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Solution Update firmware to the latest version.
Credit DEVCORE
Public Date 2019-10-17
Top