Information Leak Vulnerability in ZTE F6x2W Product
CVE-2020-6862

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 January 2020

What is CVE-2020-6862?

The ZTE F6x2W product versions V6.0.10P2T2 and V6.0.10P2T5 are susceptible to an information leak vulnerability. Unauthorized users are able to bypass authentication requirements, accessing sensitive page information without the need to verify their identity through a CAPTCHA. This flaw presents a significant security risk, potentially allowing malicious actors to exploit the system.

Affected Version(s)

F6x2W V6.0.10P2T2?V6.0.10P2T5

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.