CVE-2024-22069

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxv10_et301_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxv10_et301:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zte:zxv10_xt802_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxv10_xt802:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-08 08:15

Updated : 2024-08-20 17:22


NVD link : CVE-2024-22069

Mitre link : CVE-2024-22069

CVE.ORG link : CVE-2024-22069


JSON object : View

Products Affected

zte

  • zxv10_xt802
  • zxv10_et301_firmware
  • zxv10_et301
  • zxv10_xt802_firmware
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo