PT-2022-24708 · Zte · Zte Mf286R

Published

2022-11-22

·

Updated

2025-04-29

·

CVE-2022-39066

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZTE MF286R (affected versions not specified)
Description The issue is related to a SQL injection vulnerability due to insufficient validation of the input parameters of the phonebook interface. An authenticated attacker could use this to execute arbitrary SQL injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-39066

Affected Products

Zte Mf286R