CVE-2023-25645: High severity zte up t2 4k vulnerability
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-25645.
What is the severity of CVE-2023-25645?
The severity of CVE-2023-25645 is high with a severity value of 7.7.
What is the affected software of CVE-2023-25645?
The affected software of CVE-2023-25645 are ZTE Up T2 4k Firmware, ZTE Zxv10 B866v2-h Firmware, ZTE Zxv10 B866v2 Firmware, ZTE Zxv10 B860h V5d0 Firmware, and ZTE Zxv10 B866v2f Firmware.
What is the description of CVE-2023-25645?
CVE-2023-25645 is a permission and access control vulnerability in some ZTE AndroidTV STBs, allowing non-privileged applications to perform protected functions and potentially clear personal data and apps.
Is there a fix available for CVE-2023-25645?
It is recommended to update the affected ZTE firmware versions to the latest versions provided by ZTE to fix CVE-2023-25645.