← Back to all advisories
High

Verizon MiFi Invalidated CSRF Token for File Uploads

Advisory ID
L9-46-493
Category
Remote File Inclusion
Vendor
Verizon
Product
Verizon MiFi 6620L
Affected Version
4.5
First Published
February 9, 2022
Last Updated
January 22, 2024
Impact
High

Risk Summary

The Verizon MiFi 6620L, version 4.5, allows an unauthenticated threat actor to upload an arbitrary file to any location on the device through the web interface. While a CSRF token is present, it is not validated by the server when uploading the file.

Technical Details

An unauthenticated threat actor can send a multipart/form-data POST request to http://my.jetpack/ with an arbitrary file in the body. By default the file is saved to the '/tmp' directory. However, the 'filename' parameter is not correctly sanitized, allowing a user to save the file to any location by prepending '../' to the file location. The web interface runs as the 'lighttpd' user; sensitive files owned by that user, including '/sysconf/ui_config.xml', can be modified through this upload.

A victim can be tricked into clicking a malicious link that uses JavaScript to upload a modified 'ui_config.xml', altering device settings such as the web interface password, removing web authentication, and modifying the QML source used by the device UI.

Chained with the 'Escalated Privileges through Backup Restore Function' issue, a full device compromise is possible: the victim clicks a malicious link, JavaScript uploads a modified WiFi.qml and ui_config.xml that disable authentication on reboot, the device reboots, and a subsequent menu interaction triggers a malicious QML that retrieves a valid CSRF token and uploads a backup configuration containing a root crontab and busybox, creating a reverse shell back to the attacker with root access.

A proof-of-concept video is available here.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 MigrationProduct Tour
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLWPostmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory Affairs
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%Not a Pentest. Not a Scanner.MDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Consultants
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRegulatory GuidesWebinarsThe Death of PentestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo