CVE-2020-6872
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>.
El módulo del software de administración del servidor de ZTE presenta una vulnerabilidad de tipo XSS almacenado. El atacante inserta algunos códigos de ataque por medio de la página de inicio de sesión en primer plano, lo que causará que un usuario ejecute un script malicioso predefinido en el navegador. Esto afecta a las versiones (R5300G4V03.08.0100/V03.07.0300/ V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/ V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.002043; R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/ V03.05.0020; R5500G4V03.08.0100/V03.07.0200/V03.07.0100/ V03.06.0100)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-13 CVE Reserved
- 2020-07-20 CVE Published
- 2023-04-05 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013203 | 2020-07-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zte Search vendor "Zte" | R8500g4 Firmware Search vendor "Zte" for product "R8500g4 Firmware" | 03.05.0020 Search vendor "Zte" for product "R8500g4 Firmware" and version "03.05.0020" | - |
Affected
| in | Zte Search vendor "Zte" | R8500g4 Search vendor "Zte" for product "R8500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R8500g4 Firmware Search vendor "Zte" for product "R8500g4 Firmware" | 03.05.0400 Search vendor "Zte" for product "R8500g4 Firmware" and version "03.05.0400" | - |
Affected
| in | Zte Search vendor "Zte" | R8500g4 Search vendor "Zte" for product "R8500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R8500g4 Firmware Search vendor "Zte" for product "R8500g4 Firmware" | 03.06.0100 Search vendor "Zte" for product "R8500g4 Firmware" and version "03.06.0100" | - |
Affected
| in | Zte Search vendor "Zte" | R8500g4 Search vendor "Zte" for product "R8500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R8500g4 Firmware Search vendor "Zte" for product "R8500g4 Firmware" | 03.07.0101 Search vendor "Zte" for product "R8500g4 Firmware" and version "03.07.0101" | - |
Affected
| in | Zte Search vendor "Zte" | R8500g4 Search vendor "Zte" for product "R8500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R8500g4 Firmware Search vendor "Zte" for product "R8500g4 Firmware" | 03.07.0103 Search vendor "Zte" for product "R8500g4 Firmware" and version "03.07.0103" | - |
Affected
| in | Zte Search vendor "Zte" | R8500g4 Search vendor "Zte" for product "R8500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5500g4 Firmware Search vendor "Zte" for product "R5500g4 Firmware" | 03.06.0100 Search vendor "Zte" for product "R5500g4 Firmware" and version "03.06.0100" | - |
Affected
| in | Zte Search vendor "Zte" | R5500g4 Search vendor "Zte" for product "R5500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5500g4 Firmware Search vendor "Zte" for product "R5500g4 Firmware" | 03.07.0100 Search vendor "Zte" for product "R5500g4 Firmware" and version "03.07.0100" | - |
Affected
| in | Zte Search vendor "Zte" | R5500g4 Search vendor "Zte" for product "R5500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5500g4 Firmware Search vendor "Zte" for product "R5500g4 Firmware" | 03.07.0200 Search vendor "Zte" for product "R5500g4 Firmware" and version "03.07.0200" | - |
Affected
| in | Zte Search vendor "Zte" | R5500g4 Search vendor "Zte" for product "R5500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5500g4 Firmware Search vendor "Zte" for product "R5500g4 Firmware" | 03.08.0100 Search vendor "Zte" for product "R5500g4 Firmware" and version "03.08.0100" | - |
Affected
| in | Zte Search vendor "Zte" | R5500g4 Search vendor "Zte" for product "R5500g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.04.0020 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.04.0020" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.05.0040 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.05.0040" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.05.0043 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.05.0043" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.05.0044 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.05.0044" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.05.0045 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.05.0045" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.05.0046 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.05.0046" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.05.0047 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.05.0047" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.07.0100 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.07.0100" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.07.0108 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.07.0108" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.07.0200 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.07.0200" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.07.0300 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.07.0300" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|
Zte Search vendor "Zte" | R5300g4 Firmware Search vendor "Zte" for product "R5300g4 Firmware" | 03.08.0100 Search vendor "Zte" for product "R5300g4 Firmware" and version "03.08.0100" | - |
Affected
| in | Zte Search vendor "Zte" | R5300g4 Search vendor "Zte" for product "R5300g4" | - | - |
Safe
|