Unrated severityNVD Advisory· Published Dec 1, 2020· Updated Aug 4, 2024
CVE-2020-6880
CVE-2020-6880
Description
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.
Affected products
2- ZXELINK/ZXELINK wireless controllerdescription
- Range: < MIPS_A_1022IPV6R3T6P7Y20
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.zxelink.com.cn/website/html/CommonContent.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.