CVE-2022-39070
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2022
Last modified:
29/04/2025
Description
There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zte:zxa10_c350m_firmware:*:*:*:*:*:*:*:* | 2.1.0 (including) | 2.1.0xgp002.4 (excluding) |
| cpe:2.3:h:zte:zxa10_c350m:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zte:zxa10_c300m_firmware:*:*:*:*:*:*:*:* | 2.1.0 (including) | 2.1.0xgp002.4 (excluding) |
| cpe:2.3:h:zte:zxa10_c300m:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



