CVE-2019-7746: Jio JMR1140 Firmware

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to change the Wi-Fi password or perform a factory reset.

Affected products

  • Jio JMR1140 Firmware: version amtel_jmr1140_r12.07 only

Published 2019-05-07. Last modified 2026-06-17.