CVE-2015-7255: Infoleak
ZTE OX-330P, ZXHN H108N, W300V1.0.0SZRDTR1D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7255?
CVE-2015-7255 has a moderate severity rating due to the potential for man-in-the-middle attacks.
How do I fix CVE-2015-7255?
To fix CVE-2015-7255, ensure that unique X.509 certificates and SSH host keys are used for each device.
What devices are affected by CVE-2015-7255?
CVE-2015-7255 affects ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, and MF28G.
What are the potential risks associated with CVE-2015-7255?
The potential risks of CVE-2015-7255 include remote attackers obtaining sensitive information through man-in-the-middle or passive decryption attacks.
Can CVE-2015-7255 be exploited remotely?
Yes, CVE-2015-7255 can be exploited remotely if the device is configured with non-unique cryptographic elements.