VulnerabilityModified
CVE-2020-6862
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability.
MEDIUM 5.3EPSS 6.31%
Does this matter?
Lower severity and a low EPSS score (6.31%). Track it; it rarely justifies an emergency change on its own.
Description
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 6.31% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-669
- Affected
- zte/f6x2w firmware
- Source
- psirt@zte.com.cn
References
- http://packetstormsecurity.com/files/159135/ZTE-F602W-CAPTCHA-Bypass.htmlExploit, Third Party Advisory, VDB Entry
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1012162Vendor Advisory
- http://packetstormsecurity.com/files/159135/ZTE-F602W-CAPTCHA-Bypass.htmlExploit, Third Party Advisory, VDB Entry
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1012162Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.