CVE Vulnerabilities

CVE-2024-22069

Improper Privilege Management

Published: Aug 08, 2024 | Modified: Aug 20, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

There is a permission and access control vulnerability of ZTEs ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Zxv10_et301_firmwareZte*v3.22.11p3 (excluding)

Potential Mitigations

References