CVE-2019-3914 is a remote command injection vulnerability affecting Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05. An authenticated attacker can exploit this by crafting a malicious hostname within an access control rule, leading to arbitrary command execution on the device. This vulnerability is rated High severity (CVSS 7.2), indicating a high impact on confidentiality, integrity, and availability, with low attack complexity. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the security community. It is not listed on CISA's KEV catalog, indicating no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
02.01.00.05CPE matchmatch criteria | cpe:2.3:o:verizon:fios_quantum_gateway_g1100_firmware:02.01.00.05:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019Verizon Fios Quantum Gateway Multiple Vulnerabilities
Apr 9, 2019