CVE-2015-7257
HIGHZTE Zxv10 W300 Firmware - Password Reset Weakness
Title source: ruleDescription
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.1674
EPSS Percentile
94.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-640
Status
draft
Affected Products (2)
zte/zxv10_w300_firmware
zte/zxv10_w300_firmware
Timeline
Published
Aug 24, 2017
Tracked Since
Feb 18, 2026