HIGH · 7.1

CVE-2024-22069

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator ill...

Vulnerability Description

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ZteZxv10 Et301 Firmware< v3.22.11p3
ZteZxv10 Et301All versions
ZteZxv10 Xt802 Firmware< v2.24.10p1
ZteZxv10 Xt802All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-22069?

CVE-2024-22069 is a vulnerability with a CVSS score of 7.1 (HIGH). There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator ill...

How severe is CVE-2024-22069?

CVE-2024-22069 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-22069?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxv10 Et301 Firmware, Zte Zxv10 Et301, Zte Zxv10 Xt802 Firmware, Zte Zxv10 Xt802.