CVE-2019-3412
Last modified
CVE-2019-3412 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.. EPSS estimates a 2.94% chance of exploitation in the next 30 days.
Description
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zte | Mf920 Firmware | < bd_r218v2.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3412?
How severe is CVE-2019-3412?
How do I fix CVE-2019-3412?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3403The /rest/api/2/user/picker rest resource in Jira before ver…5.3
- CVE-2019-3404By adding some special fields to the uri ofrouter app functi…7.5
- CVE-2019-3405In the 3.1.3.64296 and lower version of 360F5, the third par…5.3
- CVE-2019-3409All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Ou…9
- CVE-2019-3410All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Ou…4.6
- CVE-2019-3411All versions up to BD_R218V2.4 of ZTE MF920 product are impa…7.5
- CVE-2019-3413All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP produc…5.4
- CVE-2019-3414All versions up to V1.19.20.02 of ZTE OTCP product are impac…
- CVE-2019-3415ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by p…
- CVE-2019-3416All versions up to V81511329.1008 of ZTE ZXV10 B860A product…9.8
- CVE-2019-3417All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are…8.8
- CVE-2019-3418All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are…5.4
Are you affected by CVE-2019-3412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
