Vulnerability Description
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability to execute malicious scripts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxhn F670 Firmware | <= 1.1.10p3t18 |
| Zte | Zxhn F670 | - |
Related Weaknesses (CWE)
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010163Vendor Advisory
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010163Vendor Advisory
FAQ
What is CVE-2019-3418?
CVE-2019-3418 is a vulnerability with a CVSS score of 5.4 (MEDIUM). All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due to incomplete input validation, an authorized user can exploit this vulnerability...
How severe is CVE-2019-3418?
CVE-2019-3418 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3418?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxhn F670 Firmware, Zte Zxhn F670.