We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-25646

Permission and Access Control Vulnerability in ZTE H388X



Assignerzte
Reserved2023-02-09
Published2024-06-20
Updated2024-08-02

Description

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.



HIGH: 7.1CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-281 Improper Preservation of Permissions

Product status

Default status
unaffected

V10.1: AGZHM_1.3.1
affected

References

https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035844

cve.org CVE-2023-25646

nvd.nist.gov CVE-2023-25646

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.