Lucene search

K
cve[email protected]CVE-2022-39073
HistoryJan 06, 2023 - 7:15 p.m.

CVE-2022-39073

2023-01-0619:15:09
CWE-77
web.nvd.nist.gov
45
cve-2022-39073
command injection
vulnerability
zte mf286r
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

42.7%

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

Affected configurations

NVD
Node
ztemf286r_firmwareMatchnordic_mf286r_b06
AND
ztemf286rMatch-

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "MF286R",
    "versions": [
      {
        "version": "Nordic_MF286R_B06,",
        "status": "affected"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

42.7%

Related for CVE-2022-39073