All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulnerability to control the user terminal system.
References
Link | Resource |
---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010662 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: zte
Published: 2019-06-11T18:57:37
Updated: 2019-06-11T18:57:37
Reserved: 2018-12-31T00:00:00
Link: CVE-2019-3409
JSON object: View
NVD Information
Status : Modified
Published: 2019-06-11T19:29:00.810
Modified: 2020-08-24T17:37:01.140
Link: CVE-2019-3409
JSON object: View
Redhat Information
No data.
CWE