Vulnerability Details CVE-2017-10931
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-10931
-
cpe:2.3:h:zte:zxr10_160:-
-
cpe:2.3:h:zte:zxr10_1800-2s:-
-
cpe:2.3:h:zte:zxr10_2800-4:-
-
cpe:2.3:h:zte:zxr10_3800-8:-
-
cpe:2.3:o:zte:zxr10_160_firmware:-
-
cpe:2.3:o:zte:zxr10_1800-2s_firmware:-
-
cpe:2.3:o:zte:zxr10_2800-4_firmware:-
-
cpe:2.3:o:zte:zxr10_3800-8_firmware:-