There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-29582 | There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands. |
Fixes
Solution
MC801A_Elisa3_B22, MC801A1_Elisa1_B06
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: zte
Published:
Updated: 2024-08-28T14:10:23.264Z
Reserved: 2023-02-09T19:47:48.022Z
Link: CVE-2023-25643

Updated: 2024-08-02T11:25:19.324Z

Status : Modified
Published: 2023-12-14T08:15:38.357
Modified: 2024-11-21T07:49:51.263
Link: CVE-2023-25643

No data.

No data.