CVE-2024-22067
Last modified
CVE-2024-22067 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zte | Nh8091 Firmware | znh8091v1.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-22067?
How severe is CVE-2024-22067?
How do I fix CVE-2024-22067?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-22061A Heap Overflow vulnerability in WLInfoRailService component…9.8
- CVE-2024-22062There is a permissions and access control vulnerability in Z…8.8
- CVE-2024-22063The ZENIC ONE R58 products by ZTE Corporation have a command…9
- CVE-2024-22064ZTE ZXUN-ePDG product, which serves as the network node of t…6.5
- CVE-2024-22065There is a command injection vulnerability in ZTE MF258 Pro …8.8
- CVE-2024-22066There is a privilege escalation vulnerability in ZTE ZXR10 Z…6.5
- CVE-2024-22068Improper Privilege Management vulnerability in ZTE ZXR10 180…6.5
- CVE-2024-22069There is a permission and access control vulnerability of ZT…8.8
- CVE-2024-2207Potential vulnerabilities have been identified in the audio …6
- CVE-2024-22074Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 throug…9.8
- CVE-2024-22075Firefly III (aka firefly-iii) before 6.1.1 allows webhooks H…6.1
- CVE-2024-22076MyQ Print Server before 8.2 patch 43 allows remote authentic…9.8
Are you affected by CVE-2024-22067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
