There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zte
Zte mf258 Pro Firmware |
|
CPEs | cpe:2.3:o:zte:mf258_pro_firmware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zte
Zte mf258 Pro Firmware |
|
Metrics |
ssvc
|
Tue, 29 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. | |
Title | ZTE MF258 Pro product has a OS Command injection vulnerability | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: zte
Published: 2024-10-29T01:58:29.002Z
Updated: 2024-10-29T13:29:22.586Z
Reserved: 2024-01-05T01:51:09.681Z
Link: CVE-2024-22065
Vulnrichment
Updated: 2024-10-29T13:29:08.382Z
NVD
Status : Awaiting Analysis
Published: 2024-10-29T02:15:06.933
Modified: 2024-10-29T14:34:04.427
Link: CVE-2024-22065
Redhat
No data.