ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-19665 ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 14 Mar 2025 02:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 21 Nov 2024 01:45:00 +0900

Type Values Removed Values Added
First Time appeared Zte nh8091 Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:zte:nh8091:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:nh8091_firmware:znh8091v1.8:*:*:*:*:*:*:*
Vendors & Products Zte nh8091 Firmware

Tue, 19 Nov 2024 05:15:00 +0900

Type Values Removed Values Added
First Time appeared Zte
Zte nh8091
CPEs cpe:2.3:a:zte:nh8091:*:*:*:*:*:*:*:*
Vendors & Products Zte
Zte nh8091
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 16:00:00 +0900

Type Values Removed Values Added
Description ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Title ZTE NH8091 product has an improper permission control vulnerability
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2025-03-13T16:17:07.454Z

Reserved: 2024-01-05T01:51:09.681Z

Link: CVE-2024-22067

cve-icon Vulnrichment

Updated: 2024-11-18T19:31:30.730Z

cve-icon NVD

Status : Modified

Published: 2024-11-18T07:15:17.370

Modified: 2025-03-13T17:15:28.333

Link: CVE-2024-22067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses