VYPR
Unrated severityNVD Advisory· Published Jul 25, 2018· Updated Sep 17, 2024

CVE-2017-10934

CVE-2017-10934

Description

Unauthenticated RCE via Java deserialization of Apache Commons Collections in ZTE ZXIPTV-EPG Java RMI service before V5.09.02.02T4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated RCE via Java deserialization of Apache Commons Collections in ZTE ZXIPTV-EPG Java RMI service before V5.09.02.02T4.

Vulnerability

All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service with the Apache Commons Collections (ACC) library, which introduces Java deserialization vulnerabilities [1]. An unauthenticated remote attacker can exploit this by sending a crafted RMI request to the target host [1].

Exploitation

The attacker does not require any prior authentication or network position beyond reachability of the RMI service [1]. By crafting a malicious serialized Java object that leverages known ACC gadget chains, the attacker sends it as an RMI request to the server [1]. The server's deserialization of untrusted data triggers arbitrary code execution in the context of the Java RMI process [1].

Impact

Successful exploitation results in remote code execution on the target host with the privileges of the Java RMI service [1]. This allows the attacker to compromise the confidentiality, integrity, and availability of the affected system [1].

Mitigation

ZTE released version V5.09.02.02T4 to fix the vulnerability [1]. Users should upgrade to this version or later [1]. If immediate upgrade is not possible, as a workaround, administrators should firewall all exposed ports used by the server, including the RMI registry port, from any untrusted IP address [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Zte/ZXIPTVllm-create2 versions
    <V5.09.02.02T4+ 1 more
    • (no CPE)range: <V5.09.02.02T4
    • (no CPE)range: All versions prior to V5.09.02.02T4

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.