CVE-2017-10931
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.00.40 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxr10 1800 2s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.00.40 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxr10 2800 4 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.00.40 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxr10 3800 8 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.00.40 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxr10 160 | All versions |
References (2)
Source: psirt@zte.com.cn
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Timeline
No history available yet.