Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
ZXCDN-SNS V3.01.02
affected
Description
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
ZXCDN-SNS V3.01.02
References
support.zte.com.cn/...ui/bulletin/detail/3747693852734546826