Описание
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до zte.bhs.zxhnh108nr1a.h_pe (включая)
Одновременно
cpe:2.3:o:zte:zxhn_h108n_r1a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxhn_h108n_r1a:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.11222
Средний
4.9 Medium
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 4.9
github
больше 3 лет назад
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.
EPSS
Процентиль: 93%
0.11222
Средний
4.9 Medium
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-264