OS Command Injection Vulnerability in a Mobile Internet Product of ZTE

Initial Release Date:  August 25, 2023

 

Vulnerability ID

CVE ID: CVE-2023-25649         CNNVD-ID: CNNVD-2023-04118918

 

CVSS 3.1 Base Score 

6.8 Medium (AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

 

Description 

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

 

Affected Products and Fixes

Product Name

Affected Version

Resolved Version

MF286R

CR_LVWRGBMF286RV1.0.0B04

CR_LVWRGBMF286RV1.0.1B01

 

Acknowledgement

ZTE thanks Rafal Goryl (@voix44er)  for paying attention to our products and cooperating with us to disclose vulnerabilities.

 

Update Records

August 25, 2023, initial.

 

Version Update Method

A device that supports automatic update can receive a pop-up update message. You can upgrade the device accordingly. If no update message is received, contact your service provider to obtain the update information.

 

Global Customer Support Center

http://support.zte.com.cn/support/web/Contact.aspx?_langType=en

 

ZTE PSIRT

https://www.zte.com.cn/global/cybersecurity/ztepsirt.html

[Close]