Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-748x-222r-qc52

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".

EPSS

Процентиль: 95%
0.16737
Средний

7.5 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".

EPSS

Процентиль: 95%
0.16737
Средний

7.5 High

CVSS3

Дефекты

CWE-640