PT-2015-7492 · Zte · Zxhn H108N
Karn Ganeshen
·
Published
2015-12-30
·
Updated
2017-09-13
·
CVE-2015-7249
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ZTE ZXHN H108N R1A versions before ZTE.bhs.ZXHNH108NR1A.k PE
Description
The issue allows remote authenticated users to bypass intended access restrictions via a modified request. This can be demonstrated by leveraging the support account to change a password via a "cgi-bin/webproc"
accountpsd action.Recommendations
For versions before ZTE.bhs.ZXHNH108NR1A.k PE, update to ZTE.bhs.ZXHNH108NR1A.k PE or later to resolve the issue. As a temporary workaround, consider restricting access to the
accountpsd action in the "cgi-bin/webproc" endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zxhn H108N