CVE-2021-31698 - Quectel Eg25-g AT Command Injection
#2
It looks to me like an attacker would need to have compromised your pinephone already in order to exploit this issue, so to that extent it's already game over. It might be a route to installing something persistent on the modem though.

There are firmware updates from Quectel available, but I don't know if they've addressed this. There's also biktogj's firmware implementation which I think uses a different AT command handler. If that one has a similar mistake it can at least be fixed openly.
https://github.com/Biktorgj/pinephone_modem_sdk
https://github.com/Biktorgj/meta-qcom/tr...em/openqti
  Reply


Messages In This Thread
RE: CVE-2021-31698 - Quectel Eg25-g AT Command Injection - by wibble - 09-21-2021, 05:18 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  FOSS fw problem - PinePhonePro, EG25 modem dukla2000 5 465 02-05-2025, 02:30 AM
Last Post: biketool
  firmware udate Quectel EG25-G modem alwi 7 7,881 07-06-2022, 01:43 PM
Last Post: user641
  Need command to tell what modem firmware I am on. purpletiger 4 4,278 07-06-2022, 12:35 PM
Last Post: Zebulon Walton
  Quectel T-Mobile Certification and MMS manuals mouffa 2 3,640 08-08-2021, 04:28 AM
Last Post: mouffa
  Quectel EG25-G H/W interface - Operating Modes - eg25-manager mouffa 0 2,391 06-23-2021, 06:57 AM
Last Post: mouffa
  Quectel EG25-G GNSS Configuration and location tracking mouffa 2 7,272 06-07-2021, 04:24 AM
Last Post: mouffa
  Quectel EG25-G Modem Configuration - ofono - Manjaro Plasma mouffa 5 6,145 06-02-2021, 11:38 AM
Last Post: mouffa
  EG25-G support for emergency alerts (WEA/CMAS) newton688 5 8,174 07-01-2020, 11:35 AM
Last Post: wibble
  Heat build-up: EG25 or SOC? CloudHackIX 5 7,335 02-24-2020, 08:52 PM
Last Post: CloudHackIX

Forum Jump:


Users browsing this thread: 1 Guest(s)