MEDIUM🇵🇱 Wersja polska

CVE-2023-25649

CVSS 6.8v3.1pub. 2023-08-25upd. 2024-11-21

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Zte Mf286r

    HW
    Zte
    all versions
  • Zte Mf286r Firmware

    OS
    Zte
    cr_lvwrgbmf286rv1.0.0b04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-39073CRITICAL9.8PL ✓same product

Command injection w ZTE MF286R — wykonanie dowolnych poleceń

CVE-2022-39066HIGH8.8same product

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters o...

CVE-2023-25651MEDIUM4.3same product

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input valida...

CVE-2022-39072MEDIUM5.4same product

There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of...

CVE-2022-39067MEDIUM6.5same product

There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the w...