CVE-2023-25645

HIGHCVSS 7.7/10EPSS 0.27%

Last modified

CVE-2023-25645 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. EPSS estimates a 0.27% chance of exploitation in the next 30 days.

Description

There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.

Metrics

CVSS 3.1
7.7/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Probability
0.27%

17.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZteUp T2 4k Firmwarev84511302.1427
ZteZxv10 B866v2-H Firmwarev84711321.0038
ZteZxv10 B866v2-H Firmwarev84711321.0040
ZteZxv10 B866v2-H Firmwarev84711321.0045
ZteZxv10 B866v2-H Firmwarev84711321.0049
ZteZxv10 B866v2 Firmwarev82811306.3021
ZteZxv10 B866v2 Firmwarev82815416.1027
ZteZxv10 B866v2 Firmwarev82815416.1028
ZteZxv10 B866v2 Firmwarev82815416.1029
ZteZxv10 B866v2 Firmwarev82815416.2012
ZteZxv10 B866v2 Firmwarev84711309.0016
ZteZxv10 B866v2 Firmwarev84711309.0018
ZteZxv10 B866v2 Firmwarev84711309.0019
ZteZxv10 B860h V5d0 Firmwarev83011303.0049
ZteZxv10 B860h V5d0 Firmwarev83011303.0051
ZteZxv10 B860h V5d0 Firmwarev83011303.0053
ZteZxv10 B860h V5d0 Firmwarev83011303.0063
ZteZxv10 B860h V5d0 Firmwarev83011303.0069
ZteZxv10 B866v2f Firmwarev86111338.0026
ZteZxv10 B866v2f Firmwarev86111338.0031
ZteZxv10 B866v2f Firmwarev86111338.0033
ZteZxv10 B866v2f Firmwarev86111338.0035

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-25645?
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
How severe is CVE-2023-25645?
CVE-2023-25645 has a CVSS score of 7.7/10 (HIGH severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2023-25645?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-25645?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST