CVE-2023-25646

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.
Configurations

No configuration.

History

21 Nov 2024, 07:49

Type Values Removed Values Added
References () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035844 - () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035844 -

20 Jun 2024, 12:43

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de acceso no autorizado en ZTE H388X. Si H388X es causado por un craqueo del puerto serie por fuerza bruta, los atacantes con permisos de usuario comunes pueden usar esta vulnerabilidad para obtener permisos elevados en el dispositivo afectado mediante la realización de operaciones específicas.

20 Jun 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-20 07:15

Updated : 2024-11-21 07:49


NVD link : CVE-2023-25646

Mitre link : CVE-2023-25646

CVE.ORG link : CVE-2023-25646


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions