Medium severity5.4NVD Advisory· Published Jan 6, 2023· Updated Jun 17, 2026
CVE-2022-39072
CVE-2022-39072
Description
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ZTE/Mobile Internetdescription
Patches
Vulnerability mechanics
References
1- support.zte.com.cn/support/news/LoopholeInfoDetail.aspxnvdVendor Advisory
News mentions
0No linked articles in our index yet.