CVE-2017-10931
Last modified
CVE-2017-10931 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.. EPSS estimates a 1.29% chance of exploitation in the next 30 days.
Description
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxr10 1800-2s Firmware | < 3.00.40 |
| Zte | Zxr10 2800-4 Firmware | < 3.00.40 |
| Zte | Zxr10 3800-8 Firmware | < 3.00.40 |
| Zte | Zxr10 160 Firmware | < 3.00.40 |
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262Permissions Required
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10931?
How severe is CVE-2017-10931?
How do I fix CVE-2017-10931?
Are you affected by CVE-2017-10931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
