There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HZte Mf286r
HWZteall versionsZte Mf286r Firmware
OSZtecr_lvwrgbmf286rv1.0.0b04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2022-39073CRITICAL9.8PL ✓same product
Command injection w ZTE MF286R — wykonanie dowolnych poleceń
CVE-2022-39066HIGH8.8same product
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters o...
CVE-2023-25651MEDIUM4.3same product
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input valida...
CVE-2022-39072MEDIUM5.4same product
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of...
CVE-2022-39067MEDIUM6.5same product
There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the w...