First published: Thu Aug 08 2024(Updated: )
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ZTE ZXV10 ET301 Firmware | <v3.22.11p3 | |
ZTE ZXV10 ET301 Firmware | ||
All of | ||
ZTE ZXV10 XT802 | <v2.24.10p1 | |
ZTE ZXV10 Xt802 Firmware |
ZXV10 XT802:V2.24.10P1 ZXV10 ET301:V3.22.11P3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22069 is considered a critical vulnerability due to its potential to allow unauthorized access and administrative control.
To mitigate CVE-2024-22069, update to the latest firmware versions: ZXV10 XT802 firmware version 2.24.10p1 or ZXV10 ET301 firmware version 3.22.11p3.
CVE-2024-22069 affects users of ZTE's ZXV10 XT802 and ZXV10 ET301 products running specified vulnerable firmware versions.
The root cause of CVE-2024-22069 is inadequate permission and access control, allowing regular users to change administrator passwords.
Yes, attackers can exploit CVE-2024-22069 remotely by intercepting requests to change passwords on the terminal web interface.