Описание
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:zte:mf833u1_firmware:bd_mf833u1v1.0.0b01:*:*:*:*:*:*:*
cpe:2.3:h:zte:mf833u1:-:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:o:zte:mf286r_firmware:cr_lvwrgbmf286rv1.0.0b04:*:*:*:*:*:*:*
cpe:2.3:h:zte:mf286r:-:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00044
Низкий
4.3 Medium
CVSS3
8 High
CVSS3
Дефекты
CWE-20
CWE-89
Связанные уязвимости
CVSS3: 4.3
github
около 2 лет назад
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.
EPSS
Процентиль: 13%
0.00044
Низкий
4.3 Medium
CVSS3
8 High
CVSS3
Дефекты
CWE-20
CWE-89