Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25649

Опубликовано: 25 авг. 2023
Источник: nvd
CVSS3: 6.8
CVSS3: 8.8
EPSS Низкий

Описание

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zte:mf286r_firmware:cr_lvwrgbmf286rv1.0.0b04:*:*:*:*:*:*:*
cpe:2.3:h:zte:mf286r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00142
Низкий

6.8 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-77
CWE-77

Связанные уязвимости

CVSS3: 6.8
github
больше 2 лет назад

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

EPSS

Процентиль: 35%
0.00142
Низкий

6.8 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-77
CWE-77