CVE-2022-23135 Information
Jun 07, 2022
cve
Description
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization which will cause information leak and affect device operation.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
Reference
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1023444
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
6.5
Share on: