CVE-2022-39073: Command Injection
Published Jan 6, 2023
·Updated
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.
Affected Software
2 affected components
ZTE Mf286r Firmware=nordic_mf286r_b06
ZTE MF286R
Event History
Jan 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-39073?
CVE-2022-39073 is a command injection vulnerability in ZTE MF286R firmware version nordic_mf286r_b06.
2
How severe is CVE-2022-39073?
CVE-2022-39073 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
3
What is affected by CVE-2022-39073?
ZTE MF286R firmware version nordic_mf286r_b06 is affected by CVE-2022-39073.
4
How can an attacker exploit CVE-2022-39073?
An attacker can exploit CVE-2022-39073 by manipulating input parameters to execute arbitrary commands.
5
Is ZTE MF286R vulnerable to CVE-2022-39073?
ZTE MF286R is vulnerable to CVE-2022-39073 if it is running firmware version nordic_mf286r_b06.