5.5
CVSSv2

CVE-2022-23135

Published: 24/02/2022 Updated: 08/03/2022
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zte zxhn_f677_firmware

zte zxhn_f477_firmware