First published: Wed Sep 18 2024(Updated: )
There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ZTE MF296R Firmware | =mf296r_nordic1_b06 | |
ZTE MF296R Firmware |
MF296R_Nordic2_B08
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-39068 is classified as high due to its potential for denial of service attacks.
To fix CVE-2022-39068, it is recommended to update the firmware of the ZTE MF296R to the latest version provided by the manufacturer.
CVE-2022-39068 affects users of the ZTE MF296R receiving the firmware version mf296r_nordic1_b06.
CVE-2022-39068 is a buffer overflow vulnerability caused by insufficient validation of the SMS parameter length.
CVE-2022-39068 requires authenticated access, thereby limiting remote exploitation but still allowing for denial of service attacks.