There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.
2024-01-10T07:15:49.423
2024-11-21T08:21:40.457
Modified
CVSSv3.1: 5.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zte | mf258_firmware | zte_std_v1.0.0b08 | Yes |
Operating System | zte | mf258_firmware | zte_std_v1.0.0b10 | Yes |
Hardware | zte | mf258 | - | No |