← Advisories

JM-DATA ONU JF511-TV Multiple Remote Vulnerabilities

High
Advisory ID
ZSL-2022-5708
Release Date
14 June 2022
Vendor
JM-DATA GmbH - https://www.jm-data.at
Affected Version
1.0.67, 1.0.62, 1.0.55
Tested On
Boa/0.93.15
Summary

This ONU is the perfect GEPON home and business gateway. It is an all-rounder in perfection. It can BRIDGE/NAT/RIP ROUTEND and COMBINED.

Description

The device suffers from multiple vulnerabilities including: Default Credentials, CSRF, Authenticated Stored XSS and Open Redirect.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Neurogenesia
References
Changelog
14.06.2022Initial release
21.06.2022Added reference [1]
23.06.2022Added reference [2], [3], [4], [5] and [6]
24.03.2026Added reference [7], [8] and [9]