CVE-2019-3411

HIGH

ZTE MF920 Firmware <= BD_R218V2.4 - Unauthenticated Information Disclosure via WebUI Password Retrieval

Title source: llm
STIX 2.1

Description

All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 51.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
zte/mf920_firmware < bd_r218v2.4
Published Jun 11, 2019
Tracked Since Feb 18, 2026