CVE-2022-23135

MEDIUM

ZTE ZXHN F677 and F477 Firmware < 9.0.0p1n29 - Path Traversal via FTP Access Path

Title source: llm
STIX 2.1

Description

There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0037
EPSS Percentile 58.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-22
Status published
Products (2)
zte/zxhn_f477_firmware < 9.0.0p1n29
zte/zxhn_f677_firmware < 9.0.0p1n29
Published Feb 24, 2022
Tracked Since Feb 18, 2026