Vulnerability Description
Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Four-Faith | F3X24 Firmware | 1.0 |
| Four-Faith | F3X24 | - |
Related Weaknesses (CWE)
References
- https://medium.com/%40bertinjoseb/four-faith-industrial-routers-command-injectio
- https://medium.com/%40bertinjoseb/four-faith-industrial-routers-command-injectio
FAQ
What is CVE-2019-12168?
CVE-2019-12168 is a vulnerability with a CVSS score of 7.2 (HIGH). Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.
How severe is CVE-2019-12168?
CVE-2019-12168 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12168?
Check the references section above for vendor advisories and patch information. Affected products include: Four-Faith F3X24 Firmware, Four-Faith F3X24.