ID

VAR-202001-1984


TITLE

ZTE ZXR10 1800-2S multi-service router has authentication bypass vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-00235

DESCRIPTION

ZXR10 ZSR V2 series router is a next-generation intelligent access router product integrating routing, switching, wireless, security, VPN, and AC introduced by ZTE. The product uses the industry-leading hardware platform and software architecture to build Efficient, reliable, flexible and easy-to-maintain enterprise intelligence network provides an intelligent and flexible equipment platform. ZTE ZXR10 1800-2S multi-service router has an authentication bypass vulnerability. An attacker can use this vulnerability to bypass the original password authentication protection and change the password of other users.

Trust: 0.6

sources: CNVD: CNVD-2020-00235

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-00235

AFFECTED PRODUCTS

vendor:ztemodel:zxr10 1800-2s multi-service router zsrv2scope:eqversion:v2.00.20

Trust: 0.6

sources: CNVD: CNVD-2020-00235

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-00235
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-00235
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-00235

PATCH

title:ZTE ZXR10 1800-2S multi-service router has authentication bypass vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/192317

Trust: 0.6

sources: CNVD: CNVD-2020-00235

EXTERNAL IDS

db:CNVDid:CNVD-2020-00235

Trust: 0.6

sources: CNVD: CNVD-2020-00235

SOURCES

db:CNVDid:CNVD-2020-00235

LAST UPDATE DATE

2022-05-04T10:03:40.125000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-00235date:2020-01-09T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-00235date:2020-01-11T00:00:00