← Back

CVE-2022-23135

nvd nist
Published: Feb 24, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.

Affected (2)

2 products
Zxhn F677 Firmware
Zxhn F477 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.0.0p1n29
Running on/withPlatform Versions
Zte
Zxhn F677
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.0.0p1n29
Running on/withPlatform Versions
Zte
Zxhn F477
All versions

References (2)

Timeline

No history available yet.