
Canadian networking gear vendor MoFi Network appears to have patched only six of the ten vulnerabilities that security researchers had identified in the company's routers and reported since May. Among the four vulnerabilities that have not been patched are a "command injection" vulnerability and backdoors that affect the company's MOFI4500-4GXeLTE series of routers
These devices are used by many businesses, and MoFi describes them as “high-performance, rugged routers for businesses or consumers.”
MOFI4500-4GXeLTE routers provide high-bandwidth connections to business users via LTE (4G) uplinks and are typically deployed by Internet service providers or other companies that need to ensure Internet access in remote business locations where regular wired Internet connections are not available.
Researchers discovered 10 vulnerabilities in MOFI4500-4GXeLTE routers
In a recently revealed report, security firm CRITICALSTART said that a few months ago it discovered ten vulnerabilities in the firmware of MOFI4500-4GXeLTE routers .
The ten vulnerabilities caused various serious issues, which you can see in detail in the table below.

CRITICALSTART said it notified security about the vulnerabilities, but when the company issued a firmware update earlier this year, it included patches for only six of the ten bugs.
The four rows in the table in yellow refer to the four vulnerabilities that MoFi has not (yet?) patched.
MoFi has not yet commented on the revelation regarding the unpatched vulnerabilities.
Hackers could exploit the vulnerabilities
Given that the list of bugs contains several backdoors , one would expect that botnet operators would find them very attractive and exploit them.
Exploiting all ten vulnerabilities requires the attacker to simply log in to the device's web management interface, which according to CRITICALSTART, is accessible by default on all network interfaces, via LAN and WAN.
However, CRITICALSTART says that because many of MoFi's vulnerable routers are used by ISPs, some of these devices have some kind of protection, preventing easy hacks.
“Many Internet Service Providers (ISPs) use Carrier Grade NAT which prevents direct access to the management interface from the Internet,” CRITICALSTART said.
"This does not limit an attacker to access the LAN interface or the ISP's internal network. In some cases, the vulnerability can be exploited indirectly by a user clicking on a link or visiting a malicious website.".
For example, one such scenario for how these flaws could be exploited is through malicious code embedded in advertisements. When an ISP employee or a customer on the ISP's network accesses a website with one of these advertisements, the malicious code executes within the browser (located on the ISP's LAN) and compromises MoFi's MOFI4500-4GXeLTE router, on behalf of the attackers.
This means that preventing access to the router's WAN interface may not be a long-term solution, so MoFi needs to patch the remaining vulnerabilities immediately to prevent such incidents.
Due to the severity of the vulnerabilities, CRITICALSTART also notified US-CERT and the organization appears to have attempted to secure the devices.
