CVE-2023-25642: Two Vulnerabilities in Some ZTE Mobile Internet Products
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25642?
CVE-2023-25642 is considered a high-severity vulnerability due to its potential to allow denial of service attacks.
How do I fix CVE-2023-25642?
To mitigate CVE-2023-25642, ensure that you update the affected ZTE mobile internet products to the latest firmware version provided by ZTE.
Which ZTE devices are affected by CVE-2023-25642?
CVE-2023-25642 affects specific firmware versions of the ZTE MC801A and MC801A1 products.
What type of attack can be performed using CVE-2023-25642?
CVE-2023-25642 can be exploited by an authenticated attacker to perform a denial of service attack.
What is the cause of CVE-2023-25642?
CVE-2023-25642 is caused by insufficient validation of the TCP port parameter in certain ZTE mobile internet products.