CRITICAL · 9.8

CVE-2022-39070

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any ope...

Vulnerability Description

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZteZxa10 C350M Firmware>= 2.1.0, < 2.1.0xgp002.4
ZteZxa10 C350M-
ZteZxa10 C300M Firmware>= 2.1.0, < 2.1.0xgp002.4
ZteZxa10 C300M-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-39070?

CVE-2022-39070 is a vulnerability with a CVSS score of 9.8 (CRITICAL). There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any ope...

How severe is CVE-2022-39070?

CVE-2022-39070 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-39070?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxa10 C350M Firmware, Zte Zxa10 C350M, Zte Zxa10 C300M Firmware, Zte Zxa10 C300M.