CVE-2015-7249: Medium severity zte zxhn h108n firmware vulnerability
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.kPE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7249?
The severity of CVE-2015-7249 is considered to be moderate due to its potential for unauthorized access.
How do I fix CVE-2015-7249?
To fix CVE-2015-7249, update the firmware of the ZTE ZXHN H108N R1A device to the latest version provided by ZTE.
What systems are affected by CVE-2015-7249?
CVE-2015-7249 affects ZTE ZXHN H108N R1A devices running versions prior to ZTE.bhs.ZXHNH108NR1A.k_PE.
Can an attacker exploit CVE-2015-7249 remotely?
Yes, an attacker can exploit CVE-2015-7249 remotely by bypassing access restrictions with a modified request.
What kind of attack is associated with CVE-2015-7249?
CVE-2015-7249 is associated with access control vulnerabilities that allow unauthorized password changes via specific requests.