CVE-2017-10935: High severity zte zxr10 1800-2s firmware vulnerability
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10935?
CVE-2017-10935 is considered a high severity vulnerability due to its potential for unauthorized password changes.
How do I fix CVE-2017-10935?
To fix CVE-2017-10935, upgrade your ZTE ZXR10 1800-2S firmware to version 3.00.40 or later.
Who is affected by CVE-2017-10935?
All users of ZTE ZXR10 1800-2S devices with firmware versions prior to 3.00.40 are affected by CVE-2017-10935.
What type of vulnerability is CVE-2017-10935?
CVE-2017-10935 is an authentication bypass vulnerability that allows remote authenticated users to change passwords without proper authorization.
Can CVE-2017-10935 be exploited remotely?
Yes, CVE-2017-10935 can be exploited by remote authenticated users, making it particularly concerning for system security.