CVE-2023-25649: OS Command Injection Vulnerability in a Mobile Internet Product of ZTE
Published Aug 25, 2023
·Updated
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SETDEVICELED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Affected Software
2 affected components
ZTE Mf286r Firmware=cr_lvwrgbmf286rv1.0.0b04
ZTE MF286R
Remediation
Information
CR_LVWRGBMF286RV1.0.1B01
Event History
Aug 25, 2023
CVE Published
via MITRE·09:37 AM
Data Sourced
via MITRE·09:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25649?
CVE-2023-25649 is a command injection vulnerability in a mobile internet product of ZTE MF286R Firmware.
2
What is the severity of CVE-2023-25649?
CVE-2023-25649 has a severity rating of 8.8 (high).
3
How does CVE-2023-25649 work?
CVE-2023-25649 allows an authenticated attacker to execute arbitrary commands by exploiting insufficient validation of the SET_DEVICE_LED interface parameter.
4
Is ZTE MF286R affected by CVE-2023-25649?
No, ZTE MF286R is not vulnerable to CVE-2023-25649.
5
How can I mitigate the vulnerability in ZTE MF286R Firmware?
To mitigate the vulnerability in ZTE MF286R Firmware, it is recommended to apply the latest security patch provided by ZTE.