jio records
7 published records for vendor jio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-7745No exploit | JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWjio · jmr1140 firmware | Critical9.8 | — | 3.8% | May 7, 2019 |
32Monitor | CVE-2019-7746No exploit | JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser rejio · jmr1140 firmware · CWE-352 | High8.1 | — | 1.1% | May 7, 2019 |
28Monitor | CVE-2018-15181Proof of concept | JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name jio · 4g hotspot m2s firmware · CWE-79 | Medium6.5 | — | 5.3% | Aug 9, 2018 |
27Monitor | CVE-2019-7439Proof of concept | cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.jio · jiofi 4g m2s firmware | Medium6.5 | — | 4.8% | Mar 21, 2019 |
27Monitor | CVE-2019-7440Proof of concept | JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgjio · jiofi 4g m2s firmware · CWE-352 | Medium6.5 | — | 2.0% | Mar 21, 2019 |
25Monitor | CVE-2019-7438Proof of concept | cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.jio · jiofi 4g m2s firmware · CWE-79 | Medium6.1 | — | 4.0% | Mar 21, 2019 |
24Monitor | CVE-2019-7687No exploit | cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter.jio · jmr1140 firmware · CWE-79 | Medium6.1 | — | 1.6% | May 7, 2019 |
- CVE-2019-774540Plan
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetW
CriticalCVSS 9.8No exploitEPSS 4%jio · jmr1140 firmwareMay 7, 2019
- CVE-2019-774632Monitor
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser re
HighCVSS 8.1No exploitEPSS 1%jio · jmr1140 firmwareMay 7, 2019
- CVE-2018-1518128Monitor
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name
MediumCVSS 6.5Proof of conceptEPSS 5%jio · 4g hotspot m2s firmwareAug 9, 2018
- CVE-2019-743927Monitor
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
MediumCVSS 6.5Proof of conceptEPSS 5%jio · jiofi 4g m2s firmwareMar 21, 2019
- CVE-2019-744027Monitor
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cg
MediumCVSS 6.5Proof of conceptEPSS 2%jio · jiofi 4g m2s firmwareMar 21, 2019
- CVE-2019-743825Monitor
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
MediumCVSS 6.1Proof of conceptEPSS 4%jio · jiofi 4g m2s firmwareMar 21, 2019
- CVE-2019-768724Monitor
cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter.
MediumCVSS 6.1No exploitEPSS 2%jio · jmr1140 firmwareMay 7, 2019