ZTE ZXV10 XT802/ET301 Permission and Access Control Vulnerability
CVE-2024-22069
What is CVE-2024-22069?
A permission and access control vulnerability exists in ZTE's ZXV10 XT802 and ET301 products. This vulnerability allows an attacker with common user permissions to log into the terminal web interface and modify the administrator's password. By intercepting requests intended for password change operations, an unauthorized individual could escalate their access privileges, potentially leading to unauthorized control over network devices. Organizations using these products should assess their security measures and apply necessary updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ZXV10 ET301 Linux All versions up to V3.22.11P3
ZXV10 XT802 Linux All versions up to V2.24.10P1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
