SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-22067

ZTE NH8091 product has an improper permission control vulnerability.

HIGH 8.8EPSS 0.69%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
zte/nh8091 firmware
Source
psirt@zte.com.cn

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.