CVE-2022-39070

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxa10_c350m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxa10_c350m:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zte:zxa10_c300m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxa10_c300m:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:17

Type Values Removed Values Added
References () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1027824 - Vendor Advisory () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1027824 - Vendor Advisory

28 Nov 2022, 19:29

Type Values Removed Values Added
CPE cpe:2.3:o:zte:zxa10_c350m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxa10_c350m:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxa10_c300m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxa10_c300m:-:*:*:*:*:*:*:*
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1027824 - (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1027824 - Vendor Advisory

22 Nov 2022, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-22 17:15

Updated : 2024-11-21 07:17


NVD link : CVE-2022-39070

Mitre link : CVE-2022-39070

CVE.ORG link : CVE-2022-39070


JSON object : View

Products Affected

zte

  • zxa10_c300m_firmware
  • zxa10_c300m
  • zxa10_c350m
  • zxa10_c350m_firmware