7.5
CVSSv3

CVE-2017-10937

Published: 25/07/2018 Updated: 20/09/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote malicious users to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zte zxiptv-ucm_firmware