CVE-2024-45416
- EPSS 0.11%
- Veröffentlicht 16.09.2024 21:15:46
- Zuletzt bearbeitet 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them u...
CVE-2024-45413
- EPSS 0.13%
- Veröffentlicht 16.09.2024 21:15:45
- Zuletzt bearbeitet 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking ...
CVE-2024-45414
- EPSS 0.25%
- Veröffentlicht 16.09.2024 21:15:45
- Zuletzt bearbeitet 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded c...
CVE-2024-45415
- EPSS 0.21%
- Veröffentlicht 16.09.2024 21:15:45
- Zuletzt bearbeitet 20.09.2024 12:31:20
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request...
CVE-2020-6879
- EPSS 0.04%
- Veröffentlicht 19.11.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:20
Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the web management page. The restriction of the front-end code can be bypassed by constructing a POST request message and sending the re...