Description
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.
Published: 2024-10-10
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-19666 Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.
History

Fri, 07 Feb 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte zxr10 160
Zte zxr10 1800-2s
Zte zxr10 2800-4
Zte zxr10 3800-8
Weaknesses CWE-521
CPEs cpe:2.3:h:zte:zxr10_160:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_1800-2s:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_2800-4:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxr10_3800-8:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_1800-2s_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zte zxr10 160
Zte zxr10 1800-2s
Zte zxr10 2800-4
Zte zxr10 3800-8

Thu, 10 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxr10 160 Firmware
Zte zxr10 1800-2s Firmware
Zte zxr10 2800-4 Firmware
Zte zxr10 3800-8 Firmware
CPEs cpe:2.3:o:zte:zxr10_160_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_1800-2s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_2800-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxr10_3800-8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zte
Zte zxr10 160 Firmware
Zte zxr10 1800-2s Firmware
Zte zxr10 2800-4 Firmware
Zte zxr10 3800-8 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Oct 2024 09:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.
Title Weak Password Vulnerability in ZTE ZSR V2 Intelligent Multi Service Router
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H'}


Subscriptions

Zte Zxr10 160 Zxr10 160 Firmware Zxr10 1800-2s Zxr10 1800-2s Firmware Zxr10 2800-4 Zxr10 2800-4 Firmware Zxr10 3800-8 Zxr10 3800-8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2024-10-10T13:38:50.810Z

Reserved: 2024-01-05T01:51:09.681Z

Link: CVE-2024-22068

cve-icon Vulnrichment

Updated: 2024-10-10T13:38:43.390Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-10T09:15:03.190

Modified: 2025-02-07T15:32:50.550

Link: CVE-2024-22068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses