Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-7257. PoCs published by Karn Ganeshen.
AI-analyzed exploit summary The document describes multiple vulnerabilities in ZTE ADSL ZXV10 W300 modems, including insufficient authorization controls (CVE-2015-7257), sensitive information disclosure (CVE-2015-7258), and a potential backdoor account feature (CVE-2015-7259). It provides steps to reproduce each vulnerability but does not include executable exploit code.
Description
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
Exploits (1)
The document describes multiple vulnerabilities in ZTE ADSL ZXV10 W300 modems, including insufficient authorization controls (CVE-2015-7257), sensitive information disclosure (CVE-2015-7258), and a potential backdoor account feature (CVE-2015-7259). It provides steps to reproduce each vulnerability but does not include executable exploit code.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H