CVE-2019-13411: A remote command execution vulnerability was discovered in HiNet GPON firmware < I040GWR190731 port 3097
Published Oct 17, 2019
·Updated
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
2 affected components
HiNet GPON firmware<i040gwr190731
HiNet GPON
Event History
Oct 17, 2019
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-13411?
The severity of CVE-2019-13411 is critical with a CVSS score of 10.
2
What type of vulnerability is associated with CVE-2019-13411?
CVE-2019-13411 is a remote command execution vulnerability found in HiNet GPON firmware.
3
How does CVE-2019-13411 allow an attacker to exploit the system?
CVE-2019-13411 allows an attacker to execute arbitrary commands through an invalid command handler over port 3097.
4
Which firmware versions are affected by CVE-2019-13411?
CVE-2019-13411 affects HiNet GPON firmware versions prior to I040GWR190731.
5
What should users of HiNet GPON firmware do regarding CVE-2019-13411?
Users should immediately update their HiNet GPON firmware to the latest version to mitigate the risk posed by CVE-2019-13411.