First published: Thu Aug 24 2017(Updated: )
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE ZXV10 W300 | =w300v2.1.0f_er7_pe_o57 | |
ZTE ZXV10 W300 Firmware | ||
ZTE ZXV10 W300 | =w300v2.1.0h_er7_pe_o57 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7259 is classified as a high severity vulnerability due to the potential for unauthorized access to user accounts.
To mitigate CVE-2015-7259, update the firmware of the ZTE ZXV10 W300 to the latest version released by the manufacturer.
CVE-2015-7259 affects ZTE ADSL ZXV10 W300 modems running firmware versions w300v2.1.0f_ER7_PE_O57 and w300v2.1.0h_ER7_PE_O57.
Users affected by CVE-2015-7259 may face the risk of account compromise, as multiple username and password pairs can grant access.
Currently, the recommended action for CVE-2015-7259 is to update the firmware, as there are no effective workarounds available.