1 results (0.001 seconds)

CVSS: 3.5EPSS: 0%CPEs: 4EXPL: 0

Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the request to the creation of a static routing rule configuration interface. The WEB service backend fails to effectively verify the abnormal input. As a result, the attacker can successfully use the vulnerability to tamper parameter values. • http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013922 • CWE-20: Improper Input Validation •