Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23135


There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.


Published

2022-02-24T19:15:10.183

Last Modified

2024-11-21T06:48:04.507

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zte zxhn_f677_firmware < 9.0.0p1n29 Yes
Hardware zte zxhn_f677 - No
Operating System zte zxhn_f477_firmware < 9.0.0p1n29 Yes
Hardware zte zxhn_f477 - No

References