CVE-2023-25649

CVSS V2 None CVSS V3 None
Description
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Overview
  • CVE ID
  • CVE-2023-25649
  • Assigner
  • zte
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-08-25T09:37:36.684Z
  • Last Modified Date
  • 2023-08-25T09:37:36.684Z
History
Created Old Value New Value Data Type Notes
2024-06-25 17:56:27 Added to TrackCVE