Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-25649

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.4%
CVSS Severity
CVSS v3 Score 6.8
Products affected by CVE-2023-25649
  • Zte » Mf286r » Version: N/A
    cpe:2.3:h:zte:mf286r:-
  • Zte » Mf286r Firmware » Version: cr_lvwrgbmf286rv1.0.0b04
    cpe:2.3:o:zte:mf286r_firmware:cr_lvwrgbmf286rv1.0.0b04


Contact Us

Shodan ® - All rights reserved