CVE-2022-23144
23.09.2022, 15:15
There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zte | zxa10_b76hv3_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b766v2_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b800v2_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b860av2.1_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b860h_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b866v2-h_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b866v5-w10_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b960gv1_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b710c-a12_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b710s2-a19_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b836ct-a15_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_s100v_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_s200a_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_s200t_firmware | 𝑥 ≤ 2.01.02.01 |
| zte | zxa10_b700v7_firmware | 𝑥 ≤ 2.01.02.01 |
𝑥
= Vulnerable software versions