CVE Feed

    Dashboard / CVE / CVE-2020-6879

    CVE-2020-6879

    Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request to the creation of a static routing rule configuration interface. The WEB service backend fails to effectively verify the abnormal input. As a result, the attacker can successfully use the vulnerability to tamper parameter values. This affects: ZXHN Z500 V1.0.0.2B1.1000 and ZXHN F670L V1.1.10P1N2E. This is fixed in ZXHN Z500 V1.0.1.1B1.1000 and ZXHN F670L V1.1.10P2N2.

    Published:Nov 19, 2020
    Last Modified:Nov 21, 2024
    EPS:Nov 19, 2020
    EPSS Score:0.00142
    CVSS Score:3.5

    Affected Products

    Vendor
    Zte
    Product
    Zxhn F670l
    Vendor
    Zte
    Product
    Zxhn F670l Firmware
    Vendor
    Zte
    Product
    Zxhn Z500
    Vendor
    Zte
    Product
    Zxhn Z500 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High