A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E
References
| Link | Resource |
|---|---|
| https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1015964 | Vendor Advisory |
| https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1015964 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2021-06-10 12:15
Updated : 2024-11-21 05:48
NVD link : CVE-2021-21736
Mitre link : CVE-2021-21736
CVE.ORG link : CVE-2021-21736
JSON object : View
Products Affected
zte
- zxhn_hs562
- zxhn_hs562_firmware
CWE
CWE-276
Incorrect Default Permissions
