Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZTE ZXIPTV-EPG 安全漏洞
Vulnerability Description
ZTE ZXIPTV-EPG中国中兴通讯(ZTE)公司的一款机顶盒设备。 ZTE ZXIPTV-EPG 5.09.02.02T4之前版本中存在Java反序列化漏洞,该漏洞源于在所使用的Java RMI服务中,服务器使用了Apache Commons Collections (ACC)库。远程攻击者可通过发送特制的请求利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A