logo

Uncovering FileWave Mobile Device Management (MDM) Vulnerabilities

ID: 5af6d521-c214-5d84-8188-52b84d75afa7

STIX ID: report--5af6d521-c214-5d84-8188-52b84d75afa7

Feed Name: Claroty Team82

Threat Score
78/100

Date Published: 2023-08-16

Date Updated: 2026-04-17

Author: Noam Moshe

...
...

Team82 disclosed two critical vulnerabilities in FileWave MDM that allow authentication bypass (using a hard-coded scheduler secret and Host header manipulation) and a hard-coded cryptographic key; exploiting these flaws yields superuser access to MDM servers, enabling exfiltration of device data and remote deployment of malicious packages (demonstrated with a fake ransomware payload). The researchers identified over 1,100 internet-facing vulnerable instances across sectors, provided technical PoC details, and coordinated disclosure with FileWave, which issued patches in v14.7.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.