Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6w5-xcrq-hc6g

Опубликовано: 29 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

EPSS

Процентиль: 47%
0.00238
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20
CWE-78

Связанные уязвимости

CVSS3: 6.8
nvd
больше 1 года назад

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

EPSS

Процентиль: 47%
0.00238
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20
CWE-78