CVE-2022-39067: Buffer Overflow
Published Nov 22, 2022
·Updated
There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial of service attack.
Affected Software
4 affected components
ZTE Mf286r Firmware<mf286r_b07
ZTE MF286R
All of the following
ZTE Mf286r Firmware<mf286r_b07
ZTE MF286R
Event History
Nov 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the buffer overflow vulnerability in ZTE MF286R?
The vulnerability ID is CVE-2022-39067.
2
What is the impact of CVE-2022-39067?
An authenticated attacker could use the vulnerability to perform a denial of service attack.
3
What software is affected by CVE-2022-39067?
ZTE MF286R with firmware versions up to and including mf286r_b07.
4
Is ZTE MF286R software version mf286r_b07 vulnerable to CVE-2022-39067?
Yes, ZTE MF286R software version mf286r_b07 is vulnerable to CVE-2022-39067.
5
How can I fix CVE-2022-39067?
Apply the latest firmware update provided by ZTE to fix the vulnerability.