ID

VAR-201905-1300


CVE

CVE-2019-12168


TITLE

Four-Faith Wireless Mobile Router F3x24 Command injection vulnerability in devices

Trust: 0.8

sources: JVNDB: JVNDB-2019-004688

DESCRIPTION

Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen. Four-Faith Wireless Mobile Router F3x24 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Four-Faith WirelessMobileRouter F3x24 is a portable wireless mobile router from China's Four-Faith. A code execution vulnerability exists in the Four-Faith WirelessMobileRouter F3x24v1.0 release, which can be exploited by a remote attacker using the CommandShell interface

Trust: 2.25

sources: NVD: CVE-2019-12168 // JVNDB: JVNDB-2019-004688 // CNVD: CNVD-2019-14844 // VULHUB: VHN-143887

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-14844

AFFECTED PRODUCTS

vendor:four faithmodel:f3x24scope:eqversion:1.0

Trust: 1.0

vendor:four faith communicationmodel:f3x24scope:eqversion:1.0

Trust: 0.8

vendor:sixin communicationmodel:wireless mobile router f3x24scope:eqversion:v1.0

Trust: 0.6

sources: CNVD: CNVD-2019-14844 // JVNDB: JVNDB-2019-004688 // NVD: CVE-2019-12168

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-12168
value: HIGH

Trust: 1.0

NVD: CVE-2019-12168
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-14844
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201905-789
value: HIGH

Trust: 0.6

VULHUB: VHN-143887
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-12168
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-14844
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-143887
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-12168
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-14844 // VULHUB: VHN-143887 // JVNDB: JVNDB-2019-004688 // CNNVD: CNNVD-201905-789 // NVD: CVE-2019-12168

PROBLEMTYPE DATA

problemtype:CWE-862

Trust: 1.1

problemtype:CWE-77

Trust: 0.9

sources: VULHUB: VHN-143887 // JVNDB: JVNDB-2019-004688 // NVD: CVE-2019-12168

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201905-789

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-201905-789

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-004688

PATCH

title:Top Pageurl:https://en.four-faith.com/

Trust: 0.8

sources: JVNDB: JVNDB-2019-004688

EXTERNAL IDS

db:NVDid:CVE-2019-12168

Trust: 3.1

db:JVNDBid:JVNDB-2019-004688

Trust: 0.8

db:CNNVDid:CNNVD-201905-789

Trust: 0.7

db:CNVDid:CNVD-2019-14844

Trust: 0.6

db:VULHUBid:VHN-143887

Trust: 0.1

sources: CNVD: CNVD-2019-14844 // VULHUB: VHN-143887 // JVNDB: JVNDB-2019-004688 // CNNVD: CNNVD-201905-789 // NVD: CVE-2019-12168

REFERENCES

url:https://medium.com/@bertinjoseb/four-faith-industrial-routers-command-injection-rce-reverse-shell-121c4dedb0d8

Trust: 1.5

url:https://nvd.nist.gov/vuln/detail/cve-2019-12168

Trust: 1.4

url:https://medium.com/%40bertinjoseb/four-faith-industrial-routers-command-injection-rce-reverse-shell-121c4dedb0d8

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-12168

Trust: 0.8

url:https://web.nvd.nist.gov//vuln/detail/cve-2019-12168

Trust: 0.6

url:https://medium.com/@bertinjoseb/four

Trust: 0.6

sources: CNVD: CNVD-2019-14844 // VULHUB: VHN-143887 // JVNDB: JVNDB-2019-004688 // CNNVD: CNNVD-201905-789 // NVD: CVE-2019-12168

SOURCES

db:CNVDid:CNVD-2019-14844
db:VULHUBid:VHN-143887
db:JVNDBid:JVNDB-2019-004688
db:CNNVDid:CNNVD-201905-789
db:NVDid:CVE-2019-12168

LAST UPDATE DATE

2024-11-23T22:25:55.507000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-14844date:2019-05-21T00:00:00
db:VULHUBid:VHN-143887date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-004688date:2019-06-06T00:00:00
db:CNNVDid:CNNVD-201905-789date:2020-08-25T00:00:00
db:NVDid:CVE-2019-12168date:2024-11-21T04:22:21.260

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-14844date:2019-05-21T00:00:00
db:VULHUBid:VHN-143887date:2019-05-17T00:00:00
db:JVNDBid:JVNDB-2019-004688date:2019-06-06T00:00:00
db:CNNVDid:CNNVD-201905-789date:2019-05-17T00:00:00
db:NVDid:CVE-2019-12168date:2019-05-17T22:29:00.390