VYPR

Mf920 Firmware

by Zte

CVEs (2)

  • CVE-2019-3412CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.03

    All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.

  • CVE-2019-3411HigJun 11, 2019
    risk 0.49cvss 7.5epss 0.01

    All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components.