CVE-2023-25651

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
14/12/2023
Last modified:
19/12/2023

Description

<br /> There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zte:mf833u1_firmware:bd_mf833u1v1.0.0b01:*:*:*:*:*:*:*
cpe:2.3:h:zte:mf833u1:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:mf286r_firmware:cr_lvwrgbmf286rv1.0.0b04:*:*:*:*:*:*:*
cpe:2.3:h:zte:mf286r:-:*:*:*:*:*:*:*