There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
References
Configurations
No configuration.
History
29 Oct 2024, 14:34
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
29 Oct 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-29 02:15
Updated : 2024-10-29 14:34
NVD link : CVE-2024-22065
Mitre link : CVE-2024-22065
CVE.ORG link : CVE-2024-22065
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation