CVE Vulnerabilities

CVE-2024-22069

Published: Aug 08, 2024 | Modified: Aug 20, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a permission and access control vulnerability of ZTEs ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

Affected Software

Name Vendor Start Version End Version
Zxv10_et301_firmware Zte * v3.22.11p3 (excluding)

References