CVE-2024-22067

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:nh8091_firmware:znh8091v1.8:*:*:*:*:*:*:*
cpe:2.3:h:zte:nh8091:-:*:*:*:*:*:*:*

History

20 Nov 2024, 16:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 8.8
References () https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/6179526095692935173 - () https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/6179526095692935173 - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Zte
Zte nh8091 Firmware
Zte nh8091
CPE cpe:2.3:o:zte:nh8091_firmware:znh8091v1.8:*:*:*:*:*:*:*
cpe:2.3:h:zte:nh8091:-:*:*:*:*:*:*:*

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) El producto ZTE NH8091 tiene una vulnerabilidad de control de permisos inadecuado. Debido al control de permisos inadecuado de la interfaz del módulo web, un atacante autenticado puede aprovechar la vulnerabilidad para ejecutar comandos arbitrarios.

18 Nov 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 07:15

Updated : 2024-11-20 16:24


NVD link : CVE-2024-22067

Mitre link : CVE-2024-22067

CVE.ORG link : CVE-2024-22067


JSON object : View

Products Affected

zte

  • nh8091_firmware
  • nh8091