CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.71% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-640
- Affected
- zte/zxv10 w300 firmware
- Source
- cret@cert.org
References
- http://packetstormsecurity.com/files/134336/ZTE-ADSL-Authorization-Bypass-Information-Disclosure.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/134493/ZTE-ADSL-ZXV10-W300-Authorization-Disclosure-Backdoor.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Nov/48Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/38772/Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/134336/ZTE-ADSL-Authorization-Bypass-Information-Disclosure.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/134493/ZTE-ADSL-ZXV10-W300-Authorization-Disclosure-Backdoor.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Nov/48Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/38772/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.