Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-6882


ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices by sending specific topics. This affects:<ZXHN E8810, ZXHN E8820, ZXHN E8822><E8810 V1.0.26, E8810 V2.0.1, E8820 V1.1.3L, E8820 V2.0.13, E8822 V2.0.13>


Published

2020-12-21T18:15:16.790

Last Modified

2024-11-21T05:36:20.817

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zte zxhn_e8810_firmware 1.0.26 Yes
Operating System zte zxhn_e8810_firmware 2.0.1 Yes
Hardware zte zxhn_e8810 - No
Operating System zte zxhn_e8820_firmware 1.1.3 Yes
Operating System zte zxhn_e8820_firmware 2.0.13 Yes
Hardware zte zxhn_e8820 - No
Operating System zte zxhn_e8822_firmware 2.0.13 Yes
Hardware zte zxhn_e8822 - No

References