ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files.
References
Link | Resource |
---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1011082 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-07-11 14:15
Updated : 2019-07-17 11:18
NVD link : CVE-2019-3415
Mitre link : CVE-2019-3415
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
zte
- zxmw_nr8000_firmware
- zxmw_nr8000