ZeroHour

CVE-2020-6882

CVSS 3.1
7.5 high
EPSS
1%p67
Published
()
Modified
Description

ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices by sending specific topics. This affects:

Vendors
zte
Products
zxhn e8810 firmware, zxhn e8820 firmware, zxhn e8822 firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.