EXODUS BLOG


Advisories

Juplink RX4-1500 Hard-coded Credential Vulnerability

SEPTEMBER 18, 2023
EIP-6a41336a Hard coded credentials exists in Juplink RX4-1500, a WiFi router. An unauthenticated attacker can exploit this vulnerability to log into the web interface or telnet service as the ‘user’ user. Vulnerability Identifiers Exodus Intelligence: EIP-6a41336a...
Read More

Juplink RX4-1500 Command Injection Vulnerability

SEPTEMBER 18, 2023
EIP-9f56ea7e A command injection exists in Juplink RX4-1500, a WiFi router. An authenticated attacker can exploit this vulnerability to achieve code execution as root. Vulnerability Identifiers Exodus Intelligence: EIP-9f56ea7e MITRE: CVE-2023-41029 Vulnerability Metrics CVSSv2 Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C CVSSv2...
Read More

Juplink RX4-1500 homemng Command Injection Vulnerability

SEPTEMBER 18, 2023
EIP-57838768 A command injection vulnerability exists in Juplink RX4-1500, a WiFi router. An authenticated attacker can exploit this vulnerability to achieve code execution as root. Vulnerability Identifiers Exodus Intelligence: EIP-57838768 MITRE: CVE-2023-41031 Vulnerability Metrics CVSSv2 Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C...
Read More

Juplink RX4-1500 Credential Disclosure Vulnerability

SEPTEMBER 18, 2023
EIP-3fd79566 A credential disclosure vulnerability exists in Juplink RX4-1500, a WiFi router. An authenticated attacker can exploit this vulnerability to achieve code execution as root. Vulnerability Identifiers Exodus Intelligence: EIP-3fd79566 MITRE: CVE-2023-41027 Vulnerability Metrics CVSSv2 Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C CVSSv2...
Read More