There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZte Zxa10 C300m
HWZteall versionsZte Zxa10 C300m Firmware
OSZte2.1.0 – 2.1.0xgp002.4 (excl.)Zte Zxa10 C350m
HWZteall versionsZte Zxa10 C350m Firmware
OSZte2.1.0 – 2.1.0xgp002.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-21728MEDIUM5.3same product
A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker ...
CVE-2024-10119CRITICAL9.8PL ✓same vendor
Command injection w routerze SECOM WRTM326 — zdalne wykonanie poleceń
CVE-2022-39073CRITICAL9.8PL ✓same vendor
Command injection w ZTE MF286R — wykonanie dowolnych poleceń
CVE-2022-23144CRITICAL9.1PL ✓same vendor
Broken access control w ZTE ZXvSTB — usuwanie domyślnych typów aplikacji
CVE-2021-21748CRITICAL9.8PL ✓same vendor
Stack-based buffer overflow w ZTE MF971R — możliwość RCE