Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25645


There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.


Published

2023-06-16T19:15:14.527

Last Modified

2024-12-12T18:15:22.180

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.7 (HIGH)

Weaknesses
  • Type: Primary
    CWE-276
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zte up_t2_4k_firmware v84511302.1427 Yes
Hardware zte up_t2_4k - No
Operating System zte zxv10_b866v2-h_firmware v84711321.0038 Yes
Operating System zte zxv10_b866v2-h_firmware v84711321.0040 Yes
Operating System zte zxv10_b866v2-h_firmware v84711321.0045 Yes
Operating System zte zxv10_b866v2-h_firmware v84711321.0049 Yes
Hardware zte zxv10_b866v2-h - No
Operating System zte zxv10_b866v2_firmware v82811306.3021 Yes
Operating System zte zxv10_b866v2_firmware v82815416.1027 Yes
Operating System zte zxv10_b866v2_firmware v82815416.1028 Yes
Operating System zte zxv10_b866v2_firmware v82815416.1029 Yes
Operating System zte zxv10_b866v2_firmware v82815416.2012 Yes
Operating System zte zxv10_b866v2_firmware v84711309.0016 Yes
Operating System zte zxv10_b866v2_firmware v84711309.0018 Yes
Operating System zte zxv10_b866v2_firmware v84711309.0019 Yes
Hardware zte zxv10_b866v2 - No
Operating System zte zxv10_b860h_v5d0_firmware v83011303.0049 Yes
Operating System zte zxv10_b860h_v5d0_firmware v83011303.0051 Yes
Operating System zte zxv10_b860h_v5d0_firmware v83011303.0053 Yes
Operating System zte zxv10_b860h_v5d0_firmware v83011303.0063 Yes
Operating System zte zxv10_b860h_v5d0_firmware v83011303.0069 Yes
Hardware zte zxv10_b860h_v5d0 - No
Operating System zte zxv10_b866v2f_firmware v86111338.0026 Yes
Operating System zte zxv10_b866v2f_firmware v86111338.0031 Yes
Operating System zte zxv10_b866v2f_firmware v86111338.0033 Yes
Operating System zte zxv10_b866v2f_firmware v86111338.0035 Yes
Hardware zte zxv10_b866v2f - No

References