Description
KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.
Problem types
Insufficient Session Expiration
Product status
2.0.1B1047
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5646.php (Zero Science Lab Disclosure (ZSL-2021-5646))
packetstormsecurity.com/files/161892/ (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/198471 (IBM X-Force Vulnerability Exchange Entry)
www.kzbtech.com/ (KZ TECH Vendor Homepage)
www.jatontech.com/ (JATON TEC Homepage)
neotel.mk/ (Neotel Vendor Homepage)
www.vulncheck.com/...icient-session-expiration-vulnerability (VulnCheck Advisory: KZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.