CVE-2019-12804

In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.

Scoring

Severity
HIGH
CVSS base score
7.8
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS probability
0.10%
CWE
CWE-353
Published
2019-07-10
Last modified
2026-03-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs