Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g68x-2w79-87x5

Опубликовано: 25 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

EPSS

Процентиль: 35%
0.00142
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.8
nvd
больше 2 лет назад

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

EPSS

Процентиль: 35%
0.00142
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-77