// For flags

CVE-2018-7366

 

Severity Score

6.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

El producto ZTE ZXV10 B860AV2.1, de la rama de ChinaMobile, con versiones de ICNT hasta la V1.3.3, versiones de BESTV hasta la V1.2.2, versiones de WASU hasta la V1.1.7 y MGTV hasta la V1.4.6, tiene una vulnerabilidad de omisión de autenticación, lo que podría permitir que un usuario no autorizado realice acciones no autorizadas.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-02-22 CVE Reserved
  • 2018-12-28 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-863: Incorrect Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile Firmware
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware"
< icnt_v1.3.3
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware" and version " < icnt_v1.3.3"
-
Affected
in Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile"
--
Safe
Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile Firmware
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware"
< bestv_v1.2.2
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware" and version " < bestv_v1.2.2"
-
Affected
in Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile"
--
Safe
Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile Firmware
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware"
< wasu_v1.1.7
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware" and version " < wasu_v1.1.7"
-
Affected
in Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile"
--
Safe
Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile Firmware
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware"
< mgtv_v1.4.6
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile Firmware" and version " < mgtv_v1.4.6"
-
Affected
in Zte
Search vendor "Zte"
Zxv10 B860av2.1 Chinamobile
Search vendor "Zte" for product "Zxv10 B860av2.1 Chinamobile"
--
Safe