VendorsEE4gee_wifi_mbb_firmwareall versions
Vulnerabilities

EE Limited 4GEE WiFi MBB Firmware EE60 00 05.00 25

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-14269
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive information via a JSONP endpoint, as demonstrated by passwords and SMS content.
Published 2017-09-11 · Modified
9.8EPSS 0.016
CVE-2017-14267
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSettings.
Published 2017-09-11 · Modified
8.8EPSS 0.007
CVE-2017-14268
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have XSS in the sms_content parameter in a getSMSlist request.
Published 2017-09-11 · Modified
6.1EPSS 0.007