CVE-2017-10931: Path Traversal
Published Sep 19, 2017
·Updated
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
Affected Software
10 affected components
ZTE Zxr10 1800-2s Firmware<=-
ZTE ZXR10 1800-2S
All of the following
ZTE Zxr10 1800-2s Firmware<3.00.40
ZTE ZXR10 1800-2S
All of the following
ZTE Zxr10 2800-4 Firmware<3.00.40
ZTE ZXR10 2800-4
All of the following
ZTE Zxr10 3800-8 Firmware<3.00.40
ZTE ZXR10 3800-8
All of the following
ZTE Zxr10 160 Firmware<3.00.40
ZTE ZXR10 160
Event History
Sep 19, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-10931?
CVE-2017-10931 is rated as a medium severity vulnerability due to its potential for information leaks.
2
How do I fix CVE-2017-10931?
To fix CVE-2017-10931, upgrade the ZXR10 1800-2S firmware to version 3.00.40 or later.
3
What type of information can be leaked through CVE-2017-10931?
CVE-2017-10931 can lead to the leakage of sensitive information including system configuration files.
4
Which devices are affected by CVE-2017-10931?
CVE-2017-10931 affects ZTE ZXR10 1800-2S devices running firmware versions prior to 3.00.40.
5
Is CVE-2017-10931 a remote vulnerability?
Yes, CVE-2017-10931 can be exploited remotely by web users to download unauthorized files.