There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: zte
Published: 2023-12-14T07:19:08.757Z
Updated: 2024-08-28T14:10:23.264Z
Reserved: 2023-02-09T19:47:48.022Z
Link: CVE-2023-25643
Vulnrichment
Updated: 2024-08-02T11:25:19.324Z
NVD
Status : Modified
Published: 2023-12-14T08:15:38.357
Modified: 2024-11-21T07:49:51.263
Link: CVE-2023-25643
Redhat
No data.