There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
References
Link | Resource |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1036424 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-08-08 08:15
Updated : 2024-08-20 17:22
NVD link : CVE-2024-22069
Mitre link : CVE-2024-22069
CVE.ORG link : CVE-2024-22069
JSON object : View
Products Affected
zte
- zxv10_xt802
- zxv10_et301_firmware
- zxv10_et301
- zxv10_xt802_firmware
CWE