CVE-2015-8703
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
30/12/2015
Last modified:
12/04/2025
Description
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zte:zxhn_h108n_r1a_firmware:*:*:*:*:*:*:*:* | zte.bhs.zxhnh108nr1a.h_pe (including) | |
| cpe:2.3:h:zte:zxhn_h108n_r1a:*:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zte:zxv10_w300_firmware:*:*:*:*:*:*:*:* | w300v1.0.0f_er1_pe (including) | |
| cpe:2.3:h:zte:zxv10_w300:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



