CVE-2022-39070

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2022
Last modified:
29/04/2025

Description

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zte:zxa10_c350m_firmware:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.0xgp002.4 (excluding)
cpe:2.3:h:zte:zxa10_c350m:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxa10_c300m_firmware:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.0xgp002.4 (excluding)
cpe:2.3:h:zte:zxa10_c300m:-:*:*:*:*:*:*:*