PT-2018-18047 · Zte · Zte Zxhn F670

Maxim Goryachy

·

Published

2018-11-16

·

Updated

2019-10-09

·

CVE-2018-7360

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZTE ZXHN F670 versions prior to V1.1.10P3T18
Description The issue allows an unauthenticated attacker to obtain the GPON SN information via the appviahttp service, potentially leading to information exposure.
Recommendations For versions prior to V1.1.10P3T18, consider restricting access to the appviahttp service until a fix is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7360

Affected Products

Zte Zxhn F670