![]() There is a directory traversal vulnerability in some home gateway products of ZTE. An attacker could modify the gateway name by inserting special characters and trigger an XSS attack when the user views the current topology of the device through the management page. ![]() There is a stored XSS vulnerability in ZTE home gateway product. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered. ZTE's ZXCDN product has a reflective XSS vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack. ZTE's MF297D product has cryptographic issues vulnerability. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. ZTE's ZXMP M721 product has a permission and access control vulnerability.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |