The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
History

Fri, 07 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte zxr10 160
Zte zxr10 160 Firmware
Zte zxr10 2800-4
Zte zxr10 2800-4 Firmware
Zte zxr10 3800-8
Zte zxr10 3800-8 Firmware
CPEs cpe:2.3:h:zte:zxr10_160:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_2800-4:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_3800-8:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_160_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_2800-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_3800-8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zte zxr10 160
Zte zxr10 160 Firmware
Zte zxr10 2800-4
Zte zxr10 2800-4 Firmware
Zte zxr10 3800-8
Zte zxr10 3800-8 Firmware
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2024-09-17T03:37:33.507Z

Reserved: 2017-07-05T00:00:00

Link: CVE-2017-10931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-09-19T14:29:00.273

Modified: 2025-03-07T14:22:47.347

Link: CVE-2017-10931

cve-icon Redhat

No data.