CVE-2015-7249
MEDIUM 6.8EPSS 5.5%
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.
- CVSS v3.0
- 4.9 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:C/A:N - EPSS
- 5.53% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2015-12-30
- Updated
- 2024-08-06