CVE-2024-22069
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/08/2024
Last modified:
20/08/2024
Description
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zte:zxv10_et301_firmware:*:*:*:*:*:*:*:* | v3.22.11p3 (excluding) | |
| cpe:2.3:h:zte:zxv10_et301:*:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zte:zxv10_xt802_firmware:*:*:*:*:*:*:*:* | v2.24.10p1 (excluding) | |
| cpe:2.3:h:zte:zxv10_xt802:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



