Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZTE MF286R和ZTE MF289D SQL注入漏洞
Vulnerability Description
ZTE MF286R和ZTE MF289D都是中国中兴通讯(ZTE)公司的产品。ZTE MF286R是一款无线路由器。ZTE MF289D是一款家庭无线路由器。 ZTE Mobile MF286R、MF289D存在SQL注入漏洞,该漏洞源于NTP接口的输入参数验证不充分,攻击者利用该漏洞可以执行存储型XSS攻击,以下产品和版本受到影响:MF286R Nordic_MF286R_B06、MF289D CR_TMOCZMF289DV1.0.0B07。
CVSS Information
N/A
Vulnerability Type
N/A