Vulnerabilities > CVE-2018-7366 - Incorrect Authorization vulnerability in ZTE Zxv10 B860Av2.1 Chinamobile Firmware

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
zte
CWE-863

Summary

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

Vulnerable Configurations

Part Description Count
OS
Zte
1
Hardware
Zte
1

Common Weakness Enumeration (CWE)