CVE-2020-6882
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
21/12/2020
Last modified:
21/07/2021
Description
ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices by sending specific topics. This affects:
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:zte:zxhn_e8810_firmware:1.0.26:*:*:*:*:*:*:* | ||
cpe:2.3:o:zte:zxhn_e8810_firmware:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:h:zte:zxhn_e8810:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zte:zxhn_e8820_firmware:1.1.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:zte:zxhn_e8820_firmware:2.0.13:*:*:*:*:*:*:* | ||
cpe:2.3:h:zte:zxhn_e8820:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zte:zxhn_e8822_firmware:2.0.13:*:*:*:*:*:*:* | ||
cpe:2.3:h:zte:zxhn_e8822:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page