Vulnerability Description
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Mf258K Pro Firmware | 1.0.0b03 |
| Zte | Mf258K Pro | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-22065?
CVE-2024-22065 is a vulnerability with a CVSS score of 6.8 (MEDIUM). There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to exec...
How severe is CVE-2024-22065?
CVE-2024-22065 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22065?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Mf258K Pro Firmware, Zte Mf258K Pro.