PT-2022-15877 · Zte · Zte Zxmp M721

Published

2022-05-12

·

Updated

2022-05-23

·

CVE-2022-23139

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZTE ZXMP M721 product (affected versions not specified)
Description The issue concerns a permission and access control vulnerability. The folder permission viewed by sftp is 666, which is inconsistent with the actual permission. This inconsistency can lead to low-authority accounts obtaining higher operating permissions on key files, as users may overlook the modification of the file permission configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23139

Affected Products

Zte Zxmp M721