ZeroHour

CVE-2024-22069

CVSS 3.1
8.8 high
EPSS
<1%p18
Published
()
Modified
Description

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

Vendors
zte
Products
zxv10 et301 firmware, zxv10 xt802 firmware
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.