Vulnerability Description
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxv10 Et301 Firmware | < v3.22.11p3 |
| Zte | Zxv10 Et301 | All versions |
| Zte | Zxv10 Xt802 Firmware | < v2.24.10p1 |
| Zte | Zxv10 Xt802 | All versions |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-22069?
CVE-2024-22069 is a vulnerability with a CVSS score of 7.1 (HIGH). There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator ill...
How severe is CVE-2024-22069?
CVE-2024-22069 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22069?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxv10 Et301 Firmware, Zte Zxv10 Et301, Zte Zxv10 Xt802 Firmware, Zte Zxv10 Xt802.