Description
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
ZXCDN-SNS V3.01.02
References
support.zte.com.cn/...ui/bulletin/detail/3747693852734546826