A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the data. This affects: ZXCLOUD iRAI All versions up to KVM-ProductV6.03.04
2021-04-13T16:15:12.513
2025-01-28T15:36:03.663
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zte | zxcloud_irai | < 6.03.04 | Yes |
Application | zte | zxcloud_irai | - | No |