SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-7355

All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability.

MEDIUM 6.1EPSS 1.90%

Does this matter?

Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.

Description

All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scripting vulnerability. Due to improper neutralization of input during web page generation, an attacker could exploit this vulnerability to conduct reflected XSS or HTML injection attacks on the devices.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.90% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zte/mf65 firmware · zte/mf65m1 firmware
Source
psirt@zte.com.cn

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.