← Back to all advisories
Medium

Verizon MiFi Escalated Privileges through Backup Restore Function

Advisory ID
L9-46-492
Category
Escalated Privileges
Vendor
Verizon
Product
Verizon MiFi 6620L
Affected Version
4.5
First Published
February 9, 2022
Last Updated
January 22, 2024
Impact
Medium

Risk Summary

The backup restore function on the Verizon MiFi 6620L, version 4.5, allows a user to modify critical system files on the device such as the 'root' user's crontab file.

Technical Details

The backup restore function allows a user to upload previously saved configuration files to restore the device to a known state. The backup file is a base64-encoded, encrypted zip file. It can be encrypted and decrypted using the 'nvtl_encrypt' utility on the device. The encryption mechanism is not unique to the device, and configurations can be shared across devices.

An authenticated user can download a copy of their device's configuration file through the web interface, decode and decrypt it, then modify the zip to include a 'root' crontab file. After re-encrypting and re-encoding, the user uploads the modified configuration through the restore function. In this way the user can execute commands on the device as root through the crontab function.

Questions

Common questions about the Verizon MiFi backup restore vulnerability.

What is the Verizon MiFi backup restore vulnerability?

The backup restore function on the Verizon MiFi 6620L, version 4.5, lets a user modify critical system files on the device, including the root user crontab file. Advisory L9-46-492 lists the category as escalated privileges and the impact as Medium.

Does the MiFi backup restore attack need an account on the device?

Yes. The advisory describes an authenticated user downloading a copy of their own device configuration through the web interface, modifying it, and uploading it again through the restore function. The privilege gained is root, so this is an escalation from a normal device user rather than an unauthenticated attack.

How is the Verizon MiFi backup file protected?

The backup file is a base64 encoded, encrypted zip archive. It can be encrypted and decrypted with the nvtl_encrypt utility present on the device itself. The advisory notes the encryption mechanism is not unique to a single unit, so configurations can be shared across devices.

What does an attacker gain from the MiFi restore flaw?

The MiFi backup restore flaw gives command execution as root. By inserting a root crontab file into the modified backup archive and restoring it through the web interface, a user gets the device to run commands as root. The advisory covers Verizon MiFi 6620L version 4.5.

Can the MiFi backup restore issue be chained with other vulnerabilities?

Yes. A separate ELTON advisory, L9-46-493, covers an unauthenticated file upload on the same device where the CSRF token is not validated. That advisory describes chaining the two into a full compromise of the MiFi 6620L, ending in a reverse shell with root access.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 MigrationProduct Tour
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA-Compliant RatingsVerified ExploitabilityELTON vs. Legacy TestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Meet ELTON