There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-19664 There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0006}

epss

{'score': 0.0007}


Fri, 08 Nov 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte zxr10 160
Zte zxr10 160 Firmware
Zte zxr10 1800-2s
Zte zxr10 2800-4
Zte zxr10 2800-4 Firmware
Zte zxr10 3800-8
Zte zxr10 3800-8 Firmware
CPEs cpe:2.3:h:zte:zxr10_160:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_1800-2s:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_2800-4:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_3800-8:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_160_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_1800-2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_2800-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_3800-8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zte zxr10 160
Zte zxr10 160 Firmware
Zte zxr10 1800-2s
Zte zxr10 2800-4
Zte zxr10 2800-4 Firmware
Zte zxr10 3800-8
Zte zxr10 3800-8 Firmware

Tue, 29 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxr10 1800-2s Firmware
CPEs cpe:2.3:o:zte:zxr10_1800-2s_firmware:3.00.40:*:*:*:*:*:*:*
Vendors & Products Zte
Zte zxr10 1800-2s Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 09:15:00 +0000

Type Values Removed Values Added
Description There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2024-10-29T15:06:23.937Z

Reserved: 2024-01-05T01:51:09.681Z

Link: CVE-2024-22066

cve-icon Vulnrichment

Updated: 2024-10-29T14:39:01.154Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-29T09:15:06.800

Modified: 2024-11-08T14:31:32.933

Link: CVE-2024-22066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.