ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
History

Wed, 20 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Zte nh8091 Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:zte:nh8091:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:nh8091_firmware:znh8091v1.8:*:*:*:*:*:*:*
Vendors & Products Zte nh8091 Firmware

Mon, 18 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte nh8091
CPEs cpe:2.3:a:zte:nh8091:*:*:*:*:*:*:*:*
Vendors & Products Zte
Zte nh8091
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 07:00:00 +0000

Type Values Removed Values Added
Description ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Title ZTE NH8091 product has an improper permission control vulnerability
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published: 2024-11-18T06:45:47.446Z

Updated: 2024-11-18T19:31:36.630Z

Reserved: 2024-01-05T01:51:09.681Z

Link: CVE-2024-22067

cve-icon Vulnrichment

Updated: 2024-11-18T19:31:30.730Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T07:15:17.370

Modified: 2024-11-20T16:24:47.843

Link: CVE-2024-22067

cve-icon Redhat

No data.