Description
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-2568 | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords. |
References
History
Fri, 07 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zte zxr10 160
Zte zxr10 160 Firmware Zte zxr10 2800-4 Zte zxr10 2800-4 Firmware Zte zxr10 3800-8 Zte zxr10 3800-8 Firmware |
|
| CPEs | cpe:2.3:h:zte:zxr10_160:-:*:*:*:*:*:*:* cpe:2.3:h:zte:zxr10_2800-4:-:*:*:*:*:*:*:* cpe:2.3:h:zte:zxr10_3800-8:-:*:*:*:*:*:*:* cpe:2.3:o:zte:zxr10_160_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zte:zxr10_2800-4_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zte:zxr10_3800-8_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zte zxr10 160
Zte zxr10 160 Firmware Zte zxr10 2800-4 Zte zxr10 2800-4 Firmware Zte zxr10 3800-8 Zte zxr10 3800-8 Firmware |
|
| Metrics |
cvssV3_0
|
cvssV3_1
|
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2024-09-16T17:33:43.111Z
Reserved: 2017-07-05T00:00:00.000Z
Link: CVE-2017-10930
No data.
Status : Deferred
Published: 2017-09-19T14:29:00.227
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-10930
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD