Lucene search

K
zdiRafal Goryl (@voix44er)ZDI-23-818
HistoryJun 07, 2023 - 12:00 a.m.

(0Day) ZTE MF286R goahead Command Injection Remote Code Execution Vulnerability

2023-06-0700:00:00
Rafal Goryl (@voix44er)
www.zerodayinitiative.com
30
vulnerability
zte mf286r
command injection
remote code execution
authentication
handling
request parameter
set_device_led
system call
root access

0.001 Low

EPSS

Percentile

48.3%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ZTE MF286R routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of a request parameter provided to the SET_DEVICE_LED endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.

0.001 Low

EPSS

Percentile

48.3%

Related for ZDI-23-818