First published: Tue Jun 11 2019(Updated: )
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Mf920 Firmware | <bd_r218v2.4 | |
ZTE MF920 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-3412 is considered a high-severity vulnerability due to the potential for command execution by an attacker.
To fix CVE-2019-3412, update the firmware of the ZTE MF920 device to a version later than BD_R218V2.4.
CVE-2019-3412 affects all versions of the ZTE MF920 product up to firmware BD_R218V2.4.
CVE-2019-3412 is a command execution vulnerability caused by improper parameter verification.
Yes, an unprivileged attacker can exploit CVE-2019-3412 to execute arbitrary commands through specific interfaces.