Vulnerability Description
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | F6X2W Firmware | 6.0.10p2t2 |
| Zte | F6X2W | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/159135/ZTE-F602W-CAPTCHA-Bypass.htmlExploitThird Party AdvisoryVDB Entry
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1012162Vendor Advisory
- http://packetstormsecurity.com/files/159135/ZTE-F602W-CAPTCHA-Bypass.htmlExploitThird Party AdvisoryVDB Entry
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1012162Vendor Advisory
FAQ
What is CVE-2020-6862?
CVE-2020-6862 is a vulnerability with a CVSS score of 5.3 (MEDIUM). V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
How severe is CVE-2020-6862?
CVE-2020-6862 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6862?
Check the references section above for vendor advisories and patch information. Affected products include: Zte F6X2W Firmware, Zte F6X2W.