ZTE ZXV10 XT802/ET301 Permission and Access Control Vulnerability

CVE-2024-22069
8.8HIGH

Key Information

Vendor
Zte
Status
Zxv10 Xt802
Zxv10 Et301
Vendor
CVE Published:
8 August 2024

Summary

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

Affected Version(s)

ZXV10 XT802 < All versions up to V2.24.10P1

ZXV10 ET301 < All versions up to V3.22.11P3

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.