HIGH · 8.4

CVE-2023-25643

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnera...

Vulnerability Description

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVSS Score

8.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZteMc801A Firmwaremc801a_elisa3_b19
ZteMc801A-
ZteMc801A1 Firmwaremc801a1_elisa1_b04
ZteMc801A1-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-25643?

CVE-2023-25643 is a vulnerability with a CVSS score of 8.4 (HIGH). There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnera...

How severe is CVE-2023-25643?

CVE-2023-25643 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-25643?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Mc801A Firmware, Zte Mc801A, Zte Mc801A1 Firmware, Zte Mc801A1.