First published: Thu Aug 24 2017(Updated: )
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE ZXV10 W300 | =w300v2.1.0f_er7_pe_o57 | |
ZTE ZXV10 W300 Firmware | ||
ZTE ZXV10 W300 | =w300v2.1.0h_er7_pe_o57 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7258 is classified as a high severity vulnerability due to the risk of remote authenticated users obtaining sensitive user passwords.
CVE-2015-7258 allows remote authenticated users to access and display user passwords through a Telnet connection.
CVE-2015-7258 affects ZTE ADSL ZXV10 W300 modems running firmware versions w300v2.1.0f_er7_pe_o57 and w300v2.1.0h_er7_pe_o57.
To fix CVE-2015-7258, it is recommended to update the firmware of the ZTE ADSL ZXV10 W300 modem to a version that addresses this vulnerability.
Mitigation options for CVE-2015-7258 include disabling Telnet access or restricting it to trusted networks until a firmware update can be applied.