cancel
Showing results for 
Search instead for 
Did you mean: 
1

Ask

2

Reply

3

Solution

HIGH and CRITICAL vulnerability: CVE-2019-3411 - CVE-2019-3412 on Vodafone R218 (alias ZTE MF920)

Simonz
2: Seeker
2: Seeker

Hi,

 

There are 2 vulnerability on the Vodafone R218 mobile router, see the links:

 

NVD - Detail - cpe:2.3:o:zte:mf920_firmware:bd_r218v2.4:*:*:*:*:*:*:* (nist.gov)

 

Security Bulletin Details (zte.com.cn)

 

Actually we have the firmware BD_R218V2.4, we need the firmware BD_R218V3.0 that fixes all.

 

So I am waiting for the firmware officially released by ZTE.

 

The problem is critical and deserves full attention

9 REPLIES 9

Simonz
2: Seeker
2: Seeker

No answer from Vodafone staff...

This is the reply from official ZTE support

 

 

Simonz_0-1661774427139.png

 

Vodafone when are you going to provide this update?

 

I also like the total absence of responses from moderators, managers, administrators etc.

Beth
Community Manager
Community Manager

Hi @Simonz! I've had a read around the subject and this looks to be an issue from a few years ago where the software needed to be updated due to a potential security issue. As it's been a few years since this posting, this should be resolved and you should already be on the latest firmware that the MBB device offers as this updates regularly.

Are you able to see the firmware version you're currently using? If this is different than the one stated in the email from ZTE, please reach out to a member of the team on 191 from a Vodafone phone (03333 040191 from any other UK phone), through live chat here, or through our Social Media team here. They'll be able to reach out to our Mobile Tech agents and look into this further for you, if you're not already on the latest firmware update 🙂

Thanks for reply.

 

ALL Vodafone R218 has BD_R218V2.4, ALL mobile routers are affected, i've tested it!

 

We have the BD_R218V3.2 ready from ZTE, you just have to make it available somehow

Sent an email to the official legal mailbox Vodafone.it 1 week ago, no answer. 

 

Apparently you don't care, even if you already have the update ready available

Mark
Community Manager
Community Manager

The email address advised isn't one I'm familiar with @Simonz, so we can take a closer look into this for you, please pop our Social media team a message through the link in @Beth's message. I'm sure we'll be able to get to the bottom of this for you. 

No collaboration from the support team, i quit. I will contact the competent authorities directly. No more Vodafone, it's incredible that despite having the firmware ready from ZTE it is not distributed

Gemma
Community Manager
Community Manager

@Simonz - we do want to help. If you change your mind please reach out to us through Social Media.

Thanks for reply @Gemma ,

 

Already done, they don't have a solution/they don't know what to do.

 

You understand that when you have the solution ready and there is no collaboration, all you have to do is use other channels, i will probably contact the authorities.

 

We cannot ignore a security problem in the current conflict situation where there are dozens and dozens of cyber attacks every day.