Vulnerability Description
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Up T2 4K Firmware | v84511302.1427 |
| Zte | Up T2 4K | - |
| Zte | Zxv10 B866V2-H Firmware | v84711321.0038 |
| Zte | Zxv10 B866V2-H | - |
| Zte | Zxv10 B866V2 Firmware | v82811306.3021 |
| Zte | Zxv10 B866V2 | - |
| Zte | Zxv10 B860H V5D0 Firmware | v83011303.0049 |
| Zte | Zxv10 B860H V5D0 | - |
| Zte | Zxv10 B866V2F Firmware | v86111338.0026 |
| Zte | Zxv10 B866V2F | - |
Related Weaknesses (CWE)
References
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1031464Vendor Advisory
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1031464Vendor Advisory
FAQ
What is CVE-2023-25645?
CVE-2023-25645 is a vulnerability with a CVSS score of 7.7 (HIGH). There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signatu...
How severe is CVE-2023-25645?
CVE-2023-25645 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25645?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Up T2 4K Firmware, Zte Up T2 4K, Zte Zxv10 B866V2-H Firmware, Zte Zxv10 B866V2-H, Zte Zxv10 B866V2 Firmware.