CVE-2022-39072
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
Affected (2)
Products: Zte: Mf286r Firmware, Mf289d Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version nordic_mf286r_b06 |
| Running on/with | Platform Versions |
|---|---|
Zte Mf286r | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version cr_tmoczmf289dv1.0.0b07 |
| Running on/with | Platform Versions |
|---|---|
Zte Mf289d | All versions |
References (2)
Source: psirt@zte.com.cn
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.