First published: Thu Dec 14 2023(Updated: )
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Zte Mf833u1 Firmware | =bd_mf833u1v1.0.0b01 | |
Zte Mf833u1 | ||
All of | ||
Zte Mf286r Firmware | =cr_lvwrgbmf286rv1.0.0b04 | |
ZTE MF286R |
BD_MF833U1V1.0.0B02, CR_LVWRGBMF286RV1.0.1B01
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.