Vulnerability Description
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxr10 1800-2S Firmware | < 3.00.40 |
| Zte | Zxr10 1800-2S | - |
| Zte | Zxr10 2800-4 Firmware | < 3.00.40 |
| Zte | Zxr10 2800-4 | - |
| Zte | Zxr10 3800-8 Firmware | < 3.00.40 |
| Zte | Zxr10 3800-8 | - |
| Zte | Zxr10 160 Firmware | < 3.00.40 |
| Zte | Zxr10 160 | - |
Related Weaknesses (CWE)
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262Permissions Required
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262Permissions Required
FAQ
What is CVE-2017-10931?
CVE-2017-10931 is a vulnerability with a CVSS score of 7.5 (HIGH). The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as syste...
How severe is CVE-2017-10931?
CVE-2017-10931 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10931?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxr10 1800-2S Firmware, Zte Zxr10 1800-2S, Zte Zxr10 2800-4 Firmware, Zte Zxr10 2800-4, Zte Zxr10 3800-8 Firmware.