ZeroHour

CVE-2023-25651

CVSS 3.1
8.0 high
EPSS
<1%p27
Published
()
Modified
Description

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

Vendors
zte
Products
mf833u1 firmware, mf286r firmware
Weakness
CWE-20, CWE-89
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.