PT-2018-18047 · Zte · Zte Zxhn F670
Maxim Goryachy
·
Published
2018-11-16
·
Updated
2019-10-09
·
CVE-2018-7360
CVSS v3.1
9.6
Critical
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZTE ZXHN F670 versions prior to V1.1.10P3T18
Description
The issue allows an unauthenticated attacker to obtain the GPON SN information via the
appviahttp service, potentially leading to information exposure.Recommendations
For versions prior to V1.1.10P3T18, consider restricting access to the
appviahttp service until a fix is available.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zte Zxhn F670