PT-2024-19179 · Zte · Zte Mf258 Pro

Published

2024-10-29

·

Updated

2024-10-29

·

CVE-2024-22065

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZTE MF258 Pro (affected versions not specified)
Description The issue is related to a command injection vulnerability. It occurs due to insufficient validation of the Ping Diagnosis interface parameter, allowing an authenticated attacker to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-22065

Affected Products

Zte Mf258 Pro