Uncovering FileWave Mobile Device Management (MDM) Vulnerabilities
ID: 5af6d521-c214-5d84-8188-52b84d75afa7
STIX ID: report--5af6d521-c214-5d84-8188-52b84d75afa7
Feed Name: Claroty Team82
Team82 disclosed two critical vulnerabilities in FileWave MDM that allow authentication bypass (using a hard-coded scheduler secret and Host header manipulation) and a hard-coded cryptographic key; exploiting these flaws yields superuser access to MDM servers, enabling exfiltration of device data and remote deployment of malicious packages (demonstrated with a fake ransomware payload). The researchers identified over 1,100 internet-facing vulnerable instances across sectors, provided technical PoC details, and coordinated disclosure with FileWave, which issued patches in v14.7.2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
