VulnerabilityModified
CVE-2024-22067
ZTE NH8091 product has an improper permission control vulnerability.
HIGH 8.8EPSS 0.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- zte/nh8091 firmware
- Source
- psirt@zte.com.cn
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.