ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception message to the specified device, which will cause the device to deny service. This affects:<ZXHN E8810, ZXHN E8820, ZXHN E8822><E8810 V1.0.26, E8810 V2.0.1, E8820 V1.1.3L, E8820 V2.0.13, E8822 V2.0.13>
2020-12-21T18:15:16.713
2024-11-21T05:36:20.723
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zte | zxhn_e8810_firmware | 1.0.26 | Yes |
Operating System | zte | zxhn_e8810_firmware | 2.0.1 | Yes |
Hardware | zte | zxhn_e8810 | - | No |
Operating System | zte | zxhn_e8820_firmware | 1.1.3 | Yes |
Operating System | zte | zxhn_e8820_firmware | 2.0.13 | Yes |
Hardware | zte | zxhn_e8820 | - | No |
Operating System | zte | zxhn_e8822_firmware | 2.0.13 | Yes |
Hardware | zte | zxhn_e8822 | - | No |