There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
oryginał ENCVSS Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HZte Mf286r
HWZtewszystkie wersjeZte Mf286r Firmware
OSZtecr_lvwrgbmf286rv1.0.0b04
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2022-39073CRITICAL9.8PL ✓ten sam produkt
Command injection w ZTE MF286R — wykonanie dowolnych poleceń
CVE-2022-39066HIGH8.8ten sam produkt
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters o...
CVE-2023-25651MEDIUM4.3ten sam produkt
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input valida...
CVE-2022-39072MEDIUM5.4ten sam produkt
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of...
CVE-2022-39067MEDIUM6.5ten sam produkt
There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the w...