关键信息 CVE ID: CVE-2020-6874 CVSS 3.1 Base Score: 3.3 (Low) Description: - A ZTE product is impacted by a cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability to account credential enumeration attack or brute-force attack for password guessing. Affected Products and Fixes: - Product Name: ZXIPTV - Affected Version: ZXIPTV-WEB-PV5.09.08.04 - Resolved Version: ZXIPTV-WEB-PV5.09.08.04P3 or later Source: The vulnerability was found by ZTE's internal test. Update Records: - August 25, 2020, initial. Supporting team contacts: - ZTE GCSC hotline: 0755-26770800, 800-830-1118, 400-830-1118 - Product forum at ZTE Support website. ZTE PSIRT: psirt@zte.com.cn, PGP key ID: FF095577