logo

Proroute H685 4G router vulnerabilities

ID: 62868d00-b08a-5965-ad44-021ab734e026

STIX ID: report--62868d00-b08a-5965-ad44-021ab734e026

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-09-19

Date Updated: 2026-03-24

Author: Joe Lovett

...
...

This report details two vulnerabilities in Proroute H685t-w 4G routers running firmware 3.2.334: a high-severity authenticated command injection in the OpenConnect and PPTP admin pages enabling OS command execution upon saving settings, and a medium-severity reflected XSS in the file browser that can exfiltrate session cookies; it provides PoC HTTP requests and a Python exploit script, and advises upgrading to 3.2.335 or later, sanitizing inputs/avoiding unsafe exec calls, and enforcing HttpOnly/Secure/SameSite cookies and CSP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.