CVE-2019-3417: Command Injection
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control of user router system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3417?
CVE-2019-3417 has a high severity rating due to the potential for command injection that could allow unauthorized control of the router.
How do I fix CVE-2019-3417?
To fix CVE-2019-3417, update the affected ZTE ZXHN F670 firmware to a version higher than 1.1.10P3T18.
Who is affected by CVE-2019-3417?
All users of the ZTE ZXHN F670 router running firmware versions up to 1.1.10P3T18 are affected by CVE-2019-3417.
What are the implications of CVE-2019-3417?
The implications of CVE-2019-3417 include the possibility for an attacker to execute arbitrary commands, leading to full control over the affected router.
Is CVE-2019-3417 exploitable remotely?
Yes, CVE-2019-3417 is exploitable remotely if an attacker has authorized access to the router's management interface.