7.7

CVE-2023-25645

There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.

Data is provided by the National Vulnerability Database (NVD)
ZteUp T2 4k Firmware Versionv84511302.1427
   ZteUp T2 4k Version-
ZteZxv10 B866v2-h Firmware Versionv84711321.0038
   ZteZxv10 B866v2-h Version-
ZteZxv10 B866v2-h Firmware Versionv84711321.0040
   ZteZxv10 B866v2-h Version-
ZteZxv10 B866v2-h Firmware Versionv84711321.0045
   ZteZxv10 B866v2-h Version-
ZteZxv10 B866v2-h Firmware Versionv84711321.0049
   ZteZxv10 B866v2-h Version-
ZteZxv10 B866v2 Firmware Versionv82811306.3021
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv82815416.1027
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv82815416.1028
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv82815416.1029
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv82815416.2012
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv84711309.0016
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv84711309.0018
   ZteZxv10 B866v2 Version-
ZteZxv10 B866v2 Firmware Versionv84711309.0019
   ZteZxv10 B866v2 Version-
ZteZxv10 B860h V5d0 Firmware Versionv83011303.0049
   ZteZxv10 B860h V5d0 Version-
ZteZxv10 B860h V5d0 Firmware Versionv83011303.0051
   ZteZxv10 B860h V5d0 Version-
ZteZxv10 B860h V5d0 Firmware Versionv83011303.0053
   ZteZxv10 B860h V5d0 Version-
ZteZxv10 B860h V5d0 Firmware Versionv83011303.0063
   ZteZxv10 B860h V5d0 Version-
ZteZxv10 B860h V5d0 Firmware Versionv83011303.0069
   ZteZxv10 B860h V5d0 Version-
ZteZxv10 B866v2f Firmware Versionv86111338.0026
   ZteZxv10 B866v2f Version-
ZteZxv10 B866v2f Firmware Versionv86111338.0031
   ZteZxv10 B866v2f Version-
ZteZxv10 B866v2f Firmware Versionv86111338.0033
   ZteZxv10 B866v2f Version-
ZteZxv10 B866v2f Firmware Versionv86111338.0035
   ZteZxv10 B866v2f Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.083
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.7 2.5 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.7 2.5 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.