vendor:
ZXHN H108N
by:
Todor Donev
7,5
CVSS
HIGH
Unauthenticated config download
287
CWE
Product Name: ZXHN H108N
Affected Version From: V3.3.0_MU
Affected Version To: V3.3.0_MU
Patch Exists: NO
Related CWE: N/A
CPE: h:zte:zxhn_h108n
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
ZTE ZXHN H108N unauthenticated config download
This vulnerability allows attackers to download the config file without authentication. It does not check cookies and credentials on POST method.
Mitigation:
Ensure that authentication is required for downloading the config file.