CVE-2019-3412: OS Command Injection
All versions up to BDR218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-3412?
CVE-2019-3412 is considered a high-severity vulnerability due to the potential for command execution by an attacker.
How do I fix CVE-2019-3412?
To fix CVE-2019-3412, update the firmware of the ZTE MF920 device to a version later than BD_R218V2.4.
What products are impacted by CVE-2019-3412?
CVE-2019-3412 affects all versions of the ZTE MF920 product up to firmware BD_R218V2.4.
What type of vulnerability is CVE-2019-3412?
CVE-2019-3412 is a command execution vulnerability caused by improper parameter verification.
Can an unprivileged attacker exploit CVE-2019-3412?
Yes, an unprivileged attacker can exploit CVE-2019-3412 to execute arbitrary commands through specific interfaces.