First published: Tue Oct 29 2024(Updated: )
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE MF258 Pro | ||
All of | ||
ZTE MF258K Pro | =1.0.0b03 | |
ZTE MF258K Pro Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22065 is considered a high severity command injection vulnerability.
To fix CVE-2024-22065, it is recommended to update the ZTE MF258 Pro firmware to the latest version that addresses this vulnerability.
An authenticated attacker can exploit CVE-2024-22065 to execute arbitrary commands on the affected ZTE MF258 Pro device.
CVE-2024-22065 specifically affects the ZTE MF258 Pro product and its associated firmware versions.
Yes, exploitation of CVE-2024-22065 requires authentication to access the vulnerable Ping Diagnosis interface.