CVE-2023-25644: Denial of Service Vulnerability in Some ZTE Mobile Internet Products
Published Dec 14, 2023
·Updated
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.
Affected Software
4 affected components
All of the following
ZTE Mc801a Firmware=mc801a_elisa3_b19
ZTE Mc801a
All of the following
ZTE Mc801a1 Firmware=mc801a1_elisa1_b04
ZTE Mc801a1
Remediation
Information
MC801A_Elisa3_B22,
MC801A1_Elisa1_B06
Event History
Dec 14, 2023
CVE Published
08:04 AM
Data Sourced
08:04 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25644?
The severity of CVE-2023-25644 is classified as a denial of service vulnerability.
2
How do I fix CVE-2023-25644?
To fix CVE-2023-25644, ensure you are using the latest firmware for ZTE MC801A or MC801A1 products.
3
What products are affected by CVE-2023-25644?
CVE-2023-25644 affects ZTE MC801A and MC801A1 mobile internet products with specific firmware versions.
4
What type of attack can be performed due to CVE-2023-25644?
An attacker can exploit CVE-2023-25644 to perform a denial of service attack.
5
Is the vulnerability CVE-2023-25644 present in all ZTE products?
No, CVE-2023-25644 is specifically related to certain ZTE mobile internet product firmware versions.