Description
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.
Published: 2022-02-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-28226 There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.
History

No history.

Subscriptions

Zte Zxhn F477 Zxhn F477 Firmware Zxhn F677 Zxhn F677 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2024-08-03T03:36:19.964Z

Reserved: 2022-01-11T00:00:00.000Z

Link: CVE-2022-23135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-24T19:15:10.183

Modified: 2024-11-21T06:48:04.507

Link: CVE-2022-23135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses