ZDI-CAN-19059: ZDI-23-818: (0Day) ZTE MF286R goahead Command Injection Remote Code Execution Vulnerability
Published Jun 7, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ZTE MF286R routers. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
ZTE MF286R
Event History
Jun 7, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19059?
The severity of ZDI-CAN-19059 is considered high due to its potential to allow arbitrary code execution.
2
How do I fix ZDI-CAN-19059?
To mitigate the effects of ZDI-CAN-19059, update the ZTE MF286R router firmware to the latest version provided by the manufacturer.
3
What types of attacks can exploit ZDI-CAN-19059?
ZDI-CAN-19059 can be exploited by network-adjacent attackers to execute arbitrary code on the affected router.
4
Is authentication required to exploit ZDI-CAN-19059?
Yes, authentication is required to exploit the ZDI-CAN-19059 vulnerability.
5
Which devices are affected by ZDI-CAN-19059?
The ZTE MF286R router is specifically affected by the ZDI-CAN-19059 vulnerability.