VYPR
Critical severity9.8NVD Advisory· Published Feb 1, 2021· Updated Jun 17, 2026

CVE-2020-13858

CVE-2020-13858

Description

An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:mofinetwork:mofi4500-4gxelte_firmware:3.6.1-std:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:mofinetwork:mofi4500-4gxelte_firmware:3.6.1-std:*:*:*:*:*:*:*
    • cpe:2.3:o:mofinetwork:mofi4500-4gxelte_firmware:4.0.8-std:*:*:*:*:*:*:*
  • MoFi Network/MOFI4500-4GXeLTE-V2cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 3.6.1-std, 4.0.8-std

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.