Vulnerability Description
The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and illegally download, modify, upload, or delete files, causing improper operation of the network management system and equipment. This affects: NetNumenU31R20 V12.17.20T115
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Netnumen U31 R10 Firmware | v12.17.20t115 |
| Zte | Netnumen U31 R10 | - |
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013043Vendor Advisory
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013043Vendor Advisory
FAQ
What is CVE-2020-6870?
CVE-2020-6870 is a vulnerability with a CVSS score of 8.0 (HIGH). The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and il...
How severe is CVE-2020-6870?
CVE-2020-6870 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6870?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Netnumen U31 R10 Firmware, Zte Netnumen U31 R10.