Broken Access Control in ZTE ZXvSTB Product
CVE-2022-23144
9.1CRITICAL
What is CVE-2022-23144?
A vulnerability exists in ZTE's ZXvSTB product due to improper permission management, allowing unauthorized users to delete default application types. This access control issue can disrupt the normal functionality of the system, potentially leading to further exploitation if left unaddressed.
Affected Version(s)
ZXvSTB All versions up to ZXvSTB-CAMSV2.01.02.01