Home
MEDIUM: 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HDefault status
unaffected
BD_FLYMODEMMU5250V1.0.0B27
affected
Description
There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface.
Problem types
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Product status
BD_FLYMODEMMU5250V1.0.0B27
Credits
Duc Anh Nguyen from NTCS&TinyxLab
References
support.zte.com.cn/...ui/bulletin/detail/2657904255874650158