CVE-2023-25643: Two Vulnerabilities in Some ZTE Mobile Internet Products
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25643?
CVE-2023-25643 has been classified as a high severity vulnerability due to its command injection potential.
How do I fix CVE-2023-25643?
To fix CVE-2023-25643, update the firmware of the affected ZTE mobile internet products to a secure version that addresses the vulnerability.
Which ZTE products are affected by CVE-2023-25643?
CVE-2023-25643 affects the ZTE MC801A and MC801A1 devices running specific firmware versions.
What type of attack can be executed through CVE-2023-25643?
CVE-2023-25643 allows an authenticated attacker to execute arbitrary commands due to insufficient input validation.
Is CVE-2023-25643 exploitable remotely?
CVE-2023-25643 requires authentication, meaning an attacker must first gain access to the network products to exploit it.