Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mofinetwork

First CVE: Feb 1, 2021Active for: 5 yearsTotal CVEs: 11
46.6
VTI Score
High

Mofinetwork develops a focused line of cellular-enabled mobile broadband routers, primarily the MOFI4500 series, designed for remote connectivity and failover scenarios. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through authentication and credential-handling weaknesses—improper authentication, hard-coded credentials, missing authentication for critical functions, and improper exception handling—that are characteristic of embedded networking devices with limited update lifecycles. Defenders should prioritize inventory and network segmentation for these devices, especially in remote or mission-critical deployments; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mofinetwork over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2021
5 years ago
Most Recent CVE
Sep 8, 2023
1,050 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27715CRITICAL
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.
Sep 8, 20239.829NONO
CVE-2020-15836CRITICAL
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A
Feb 1, 20219.829NONO
CVE-2020-13858CRITICAL
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are de
Feb 1, 20219.829NONO
CVE-2020-15835CRITICAL
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root
Feb 1, 20219.824NONO
CVE-2020-15833CRITICAL
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that al
Feb 1, 20219.824NONO
CVE-2020-13859CRITICAL
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface fr
Feb 1, 20219.824NONO
CVE-2020-13856HIGH
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as
Feb 1, 20217.524NONO
CVE-2020-15834HIGH
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can d
Feb 1, 20217.523NONO
CVE-2020-13857HIGH
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.
Feb 1, 20217.523NONO
CVE-2020-15832HIGH
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device.
Feb 1, 20217.519NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
45%
55%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mofinetwork.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mofinetwork — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mofinetwork's Products

View all 1 CNAs →

Top CWEs