CVE-2024-22065

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Configurations

No configuration.

History

29 Oct 2024, 14:34

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en el producto ZTE MF258 Pro. Debido a una validación insuficiente del parámetro de interfaz Ping Diagnosis, un atacante autenticado podría usar la vulnerabilidad para ejecutar comandos arbitrarios.

29 Oct 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 02:15

Updated : 2024-10-29 14:34


NVD link : CVE-2024-22065

Mitre link : CVE-2024-22065

CVE.ORG link : CVE-2024-22065


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation