Vulnerability Description
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Mc801A Firmware | mc801a_elisa3_b19 |
| Zte | Mc801A | - |
| Zte | Mc801A1 Firmware | mc801a1_elisa1_b04 |
| Zte | Mc801A1 | - |
Related Weaknesses (CWE)
References
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032504Vendor Advisory
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032504Vendor Advisory
FAQ
What is CVE-2023-25643?
CVE-2023-25643 is a vulnerability with a CVSS score of 8.4 (HIGH). There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnera...
How severe is CVE-2023-25643?
CVE-2023-25643 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25643?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Mc801A Firmware, Zte Mc801A, Zte Mc801A1 Firmware, Zte Mc801A1.