CVE-2020-6879
Description
Authorization bypass via front-end restriction evasion in ZTE ZXHN Z500 and F670L routers allows an authenticated attacker to tamper with static routing rules.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authorization bypass via front-end restriction evasion in ZTE ZXHN Z500 and F670L routers allows an authenticated attacker to tamper with static routing rules.
Vulnerability
The ZTE ZXHN Z500 (V1.0.0.2B1.1000) and ZXHN F670L (V1.1.10P1N2E) routers contain input verification vulnerabilities. The web management interface enforces front-end restrictions for configuring a static prefix, but an attacker can bypass these by crafting a POST request directly to the static routing rule creation interface. The backend fails to validate the input, enabling parameter tampering [1].
Exploitation
An attacker must be on the same local area network (adjacent) and possess low-privileged credentials. No user interaction is required. The attack involves sending a specially crafted POST request to the vulnerable endpoint, circumventing client-side checks [1].
Impact
Successful exploitation allows the attacker to manipulate static routing parameters, potentially altering network traffic flows. Integrity is compromised, but confidentiality and availability are unaffected. The CVSS 3.1 base score is 3.5 (Low) [1].
Mitigation
ZTE has released fixed firmware versions: ZXHN Z500 V1.0.1.1B1.1000 and ZXHN F670L V1.1.10P2N2. No workarounds are documented; users should upgrade to the resolved versions [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- ZTE/ZXHN Z500description
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- support.zte.com.cn/support/news/LoopholeInfoDetail.aspxmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.