Skip to content
Noroxi

jio records

7 published records for vendor jio.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19

Bar: total · dark part: CISA KEV.

All records

7 records
  • JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetW

    CriticalCVSS 9.8No exploitEPSS 4%

    jio · jmr1140 firmwareMay 7, 2019

  • CVE-2019-7746
    32Monitor

    JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser re

    HighCVSS 8.1No exploitEPSS 1%

    jio · jmr1140 firmwareMay 7, 2019

  • JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name

    MediumCVSS 6.5Proof of conceptEPSS 5%

    jio · 4g hotspot m2s firmwareAug 9, 2018

  • CVE-2019-7439
    27Monitor

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.

    MediumCVSS 6.5Proof of conceptEPSS 5%

    jio · jiofi 4g m2s firmwareMar 21, 2019

  • CVE-2019-7440
    27Monitor

    JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cg

    MediumCVSS 6.5Proof of conceptEPSS 2%

    jio · jiofi 4g m2s firmwareMar 21, 2019

  • CVE-2019-7438
    25Monitor

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.

    MediumCVSS 6.1Proof of conceptEPSS 4%

    jio · jiofi 4g m2s firmwareMar 21, 2019

  • CVE-2019-7687
    24Monitor

    cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter.

    MediumCVSS 6.1No exploitEPSS 2%

    jio · jmr1140 firmwareMay 7, 2019