First published: Wed Dec 30 2015(Updated: )
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Zxhn H108n R1a Firmware | <=zte.bhs.zxhnh108nr1a.h_pe | |
ZTE ZXHN H108N R1A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7250 is classified as a high-severity vulnerability due to its potential for remote exploitation and unauthorized access to sensitive files.
To mitigate CVE-2015-7250, it is recommended to update the ZTE ZXHN H108N R1A firmware to a version that addresses this vulnerability.
Attackers can leverage CVE-2015-7250 to perform path traversal attacks, allowing them to read arbitrary files on the affected device.
CVE-2015-7250 affects users of the ZTE ZXHN H108N R1A devices running vulnerable firmware versions prior to ZTE.bhs.ZXHNH108NR1A.k_PE.
CVE-2015-7250 was disclosed in September 2015.