There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
2023-08-25T10:15:08.247
2024-11-21T07:49:52.010
Modified
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zte | mf286r_firmware | cr_lvwrgbmf286rv1.0.0b04 | Yes |
Hardware | zte | mf286r | - | No |