CVE-2020-6872

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/07/2020
Last modified:
24/07/2020

Description

The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects .

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zte:r8500g4_firmware:03.05.0020:*:*:*:*:*:*:*
cpe:2.3:o:zte:r8500g4_firmware:03.05.0400:*:*:*:*:*:*:*
cpe:2.3:o:zte:r8500g4_firmware:03.06.0100:*:*:*:*:*:*:*
cpe:2.3:o:zte:r8500g4_firmware:03.07.0101:*:*:*:*:*:*:*
cpe:2.3:o:zte:r8500g4_firmware:03.07.0103:*:*:*:*:*:*:*
cpe:2.3:h:zte:r8500g4:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5500g4_firmware:03.06.0100:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5500g4_firmware:03.07.0100:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5500g4_firmware:03.07.0200:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5500g4_firmware:03.08.0100:*:*:*:*:*:*:*
cpe:2.3:h:zte:r5500g4:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5300g4_firmware:03.04.0020:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5300g4_firmware:03.05.0040:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5300g4_firmware:03.05.0043:*:*:*:*:*:*:*
cpe:2.3:o:zte:r5300g4_firmware:03.05.0044:*:*:*:*:*:*:*