CVE-2020-6871

CRITICAL

ZTE R5300G4/R5500G4/R8500G4 Firmware - Authentication Bypass

Title source: llm
STIX 2.1

Description

The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0040
EPSS Percentile 61.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (21)
zte/r5300g4_firmware 03.04.0020
zte/r5300g4_firmware 03.05.0040
zte/r5300g4_firmware 03.05.0043
zte/r5300g4_firmware 03.05.0044
zte/r5300g4_firmware 03.05.0045
zte/r5300g4_firmware 03.05.0046
zte/r5300g4_firmware 03.05.0047
zte/r5300g4_firmware 03.07.0100
zte/r5300g4_firmware 03.07.0108
zte/r5300g4_firmware 03.07.0200
... and 11 more
Published Jul 20, 2020
Tracked Since Feb 18, 2026