There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.
References
Link | Resource |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1027744 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: zte
Published: 2022-11-22T00:00:00
Updated: 2022-11-22T00:00:00
Reserved: 2022-08-31T00:00:00
Link: CVE-2022-39066
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-11-22T17:15:10.017
Modified: 2022-11-30T13:32:37.447
Link: CVE-2022-39066
JSON object: View
Redhat Information
No data.
CWE