CVE-2024-22069

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/08/2024
Last modified:
20/08/2024

Description

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zte:zxv10_et301_firmware:*:*:*:*:*:*:*:* v3.22.11p3 (excluding)
cpe:2.3:h:zte:zxv10_et301:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxv10_xt802_firmware:*:*:*:*:*:*:*:* v2.24.10p1 (excluding)
cpe:2.3:h:zte:zxv10_xt802:*:*:*:*:*:*:*:*