Mofinetwork develops a focused line of cellular-enabled mobile broadband routers, primarily the MOFI4500 series, designed for remote connectivity and failover scenarios. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through authentication and credential-handling weaknesses—improper authentication, hard-coded credentials, missing authentication for critical functions, and improper exception handling—that are characteristic of embedded networking devices with limited update lifecycles. Defenders should prioritize inventory and network segmentation for these devices, especially in remote or mission-critical deployments; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mofinetwork over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27715CRITICAL An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request. | Sep 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-15836CRITICAL An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A | Feb 1, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-13858CRITICAL An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are de | Feb 1, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-15835CRITICAL An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root | Feb 1, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-15833CRITICAL An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that al | Feb 1, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-13859CRITICAL An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface fr | Feb 1, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-13856HIGH An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as | Feb 1, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-15834HIGH An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can d | Feb 1, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-13857HIGH An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request. | Feb 1, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-15832HIGH An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. | Feb 1, 2021 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mofinetwork.
Media articles that mention a CVE ID that affects a product developed by Mofinetwork — matched by CVE ID, not by vendor name.