CVE-2022-23141

HIGH

ZTE Zxmp M721 Firmware - Log Information Exposure

Title source: rule
STIX 2.1

Description

ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
zte/zxmp_m721_firmware commond21bootv100004_ls1045
Published Jul 15, 2022
Tracked Since Feb 18, 2026