Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41781


There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.


Published

2024-01-10T07:15:49.423

Last Modified

2024-11-21T08:21:40.457

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zte mf258_firmware zte_std_v1.0.0b08 Yes
Operating System zte mf258_firmware zte_std_v1.0.0b10 Yes
Hardware zte mf258 - No

References