CVE-2019-13412: A vulnerability was discovered in HiNet GPON firmware < I040GWR190731 that allows an attacker to read arbitrary files
Published Oct 17, 2019
·Updated
A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
Affected Software
2 affected components
HiNet GPON firmware<i040gwr190731
HiNet GPON
Event History
Oct 17, 2019
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-13412?
The severity of CVE-2019-13412 is classified as critical with a CVSS score of 9.3.
2
How do I fix CVE-2019-13412?
To mitigate CVE-2019-13412, upgrade to a patched version of HiNet GPON firmware that is later than I040GWR190731.
3
What does CVE-2019-13412 allow an attacker to do?
CVE-2019-13412 allows an attacker to read arbitrary files on the HiNet GPON firmware.
4
Which port is associated with CVE-2019-13412 vulnerability?
CVE-2019-13412 is associated with a vulnerability found on port 3097.
5
What type of command can be executed due to CVE-2019-13412?
CVE-2019-13412 allows executing a specific command that leads to reading arbitrary files.