ChinamobileltdCVEs & Vulnerabilities

7 CVEs affecting Chinamobileltd products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

gpn2.4p21-c-cn 5gpn2.4p21-c-cn firmware 5an lianbao wf-1 1an lianbao wf firmware-1 1oa mailbox pc 1
CVE-2023-26986HIGH

An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.

10 Apr 2023
7.8
CVSS
CVE-2020-18331CRITICAL

Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter to /cgi-bin/webproc.

27 Jan 2023
9.1
CVSS
CVE-2020-18330CRITICAL

An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), allows attackers to gain access to the configuration interface.

27 Jan 2023
9.1
CVSS
CVE-2021-33962CRITICAL

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.

14 Jan 2022
9.8
CVSS
CVE-2019-1010136HIGH

ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote.

19 Jul 2019
7.5
CVSS
CVE-2019-6282HIGHpoc

ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

21 Mar 2019
8.8
CVSS
CVE-2019-6279HIGHpoc

ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

21 Mar 2019
8.8
CVSS
← PrevPage 1 / 1Next →