Jio's vulnerability footprint concentrates in a narrow portfolio of mobile hotspot and 4G connectivity devices, including the JioFi series and related firmware, which serve consumers in emerging markets with limited device-replacement cycles. Vulnerabilities affecting these products skew toward serious outcomes, frequently acquire public exploit code, and recur through web-facing weakness classes including cross-site scripting, cross-site request forgery, and input-handling flaws that are characteristic of embedded web interfaces with limited hardening resources. Defenders should treat firmware updates for these devices as high-priority and inventory long-lived instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jio over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15181MEDIUM JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Security Key fields. | Aug 9, 2018 | 6.5 | 34 | NO | YES |
CVE-2019-7439MEDIUM cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter. | Mar 21, 2019 | 6.5 | 27 | NO | YES |
CVE-2019-7440MEDIUM JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi). | Mar 21, 2019 | 6.5 | 26 | NO | YES |
CVE-2019-7438MEDIUM cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter. | Mar 21, 2019 | 6.1 | 26 | NO | YES |
CVE-2019-7746HIGH JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. | May 7, 2019 | 8.1 | 25 | NO | NO |
CVE-2019-7745CRITICAL JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the | May 7, 2019 | 9.8 | 25 | NO | NO |
CVE-2019-7687MEDIUM cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data. | May 7, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jio.
Media articles that mention a CVE ID that affects a product developed by Jio — matched by CVE ID, not by vendor name.