VYPR
Critical severity9.8NVD Advisory· Published Jul 25, 2018· Updated Jun 17, 2026

CVE-2017-10934

CVE-2017-10934

Description

All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:zte:zxiptv-epg_firmware:*:*:*:*:*:*:*:*
    Range: <5.09.02.02t4
  • Zte/ZXIPTVllm-create2 versions
    <V5.09.02.02T4+ 1 more
    • (no CPE)range: <V5.09.02.02T4
    • (no CPE)range: All versions prior to V5.09.02.02T4
  • Range: prior to V5.09.02.02T4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.