sub_4155B4 of the file /boafrm/formLtefotaUpgradeFibocom. This manipulation of the argument fota_url causes command injection.This vulnerability is registered as CVE-2025-15191. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
SOCIAL SHARE CARD GENERATOR