PT-2019-16570 · Zte · Zxhn F670
Alexandr Shvetsov
+2
·
Published
2019-08-15
·
Updated
2023-03-02
·
CVE-2019-3418
CVSS v3.1
5.7
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZTE ZXHN F670 product versions up to V1.1.10P3T18
Description
The issue is related to a cross-site scripting vulnerability (XSS) due to incomplete input validation. An authorized user can exploit this to execute malicious scripts.
Recommendations
For versions up to V1.1.10P3T18, consider disabling any features that rely on user input validation until a patch is available.
Restrict access to sensitive areas of the product to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zxhn F670