CVE-2015-7258: Critical severity zte zxv10 w300 vulnerability
ZTE ADSL ZXV10 W300 modems W300V2.1.0fER7PEO57 and W300V2.1.0hER7PEO57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7258?
CVE-2015-7258 is classified as a high severity vulnerability due to the risk of remote authenticated users obtaining sensitive user passwords.
How does CVE-2015-7258 affect ZTE ADSL ZXV10 W300 modems?
CVE-2015-7258 allows remote authenticated users to access and display user passwords through a Telnet connection.
What versions of the ZTE ADSL ZXV10 W300 are affected by CVE-2015-7258?
CVE-2015-7258 affects ZTE ADSL ZXV10 W300 modems running firmware versions w300v2.1.0f_er7_pe_o57 and w300v2.1.0h_er7_pe_o57.
How can I fix the vulnerability CVE-2015-7258?
To fix CVE-2015-7258, it is recommended to update the firmware of the ZTE ADSL ZXV10 W300 modem to a version that addresses this vulnerability.
Can I mitigate CVE-2015-7258 without a firmware update?
Mitigation options for CVE-2015-7258 include disabling Telnet access or restricting it to trusted networks until a firmware update can be applied.