← Back

CVE-2023-25651

nvd nist
Published: Dec 14, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD

Description

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

Affected (2)

2 products
Mf833u1 Firmware
Mf286r Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version bd_mf833u1v1.0.0b01
Running on/withPlatform Versions
Zte
Mf833u1
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version cr_lvwrgbmf286rv1.0.0b04
Running on/withPlatform Versions
Zte
Mf286r
All versions

References (2)

Timeline

No history available yet.