Some ZTE devices have input verification vulnerabilities
Published Nov 19, 2020
3.5
LOWCVSS 3.1
EPSS 0.69%
Description
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request to the creation of a static routing rule configuration interface. The WEB service backend fails to effectively verify the abnormal input. As a result, the attacker can successfully use the vulnerability to tamper parameter values. This affects: ZXHN Z500 V1.0.0.2B1.1000 and ZXHN F670L V1.1.10P1N2E. This is fixed in ZXHN Z500 V1.0.1.1B1.1000 and ZXHN F670L V1.1.10P2N2.
Affected products
- Vendor n/a Product Zxhn F670l Defaultn/a
- Version Affects: V1.1.10P1N2EStatusaffectedConstraints-
- Version Fixed: V1.1.10P2N2StatusaffectedConstraints-
- Version
- Vendor n/a Product Zxhn Z500 Defaultn/a
- Version Affects: V1.0.0.2B1.1000StatusaffectedConstraints-
- Version Fixed: V1.0.1.1B1.1000StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Zxhn F670l | n/a |
| |||||||||
| n/a | Zxhn Z500 | n/a |
|
Configuration 1
- v1.0.0.2b1.1000
Configuration 2
- v1.1.10p1n2e
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013922 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013922 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.