ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
2017-08-24T20:29:00.393
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zte | zxv10_w300_firmware | w300v2.1.0f_er7_pe_o57 | Yes |
Hardware | zte | zxv10_w300 | - | No |
Operating System | zte | zxv10_w300_firmware | w300v2.1.0h_er7_pe_o57 | Yes |
Hardware | zte | zxv10_w300 | - | No |