CVE

Id
84526  
CVE No.
CVE-2015-7249  
Status
Candidate  
Description
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.  
Phase
Assigned (20150918)  
Votes
None (candidate not yet proposed)  
Comments