CVE-2022-23144

CRITICAL

ZTE ZXvSTB Firmware < 2.01.02.01 - Broken Access Control

Title source: llm
STIX 2.1

Description

There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0039
EPSS Percentile 60.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
zte/zxa10_b700v7_firmware < 2.01.02.01
zte/zxa10_b710c-a12_firmware < 2.01.02.01
zte/zxa10_b710s2-a19_firmware < 2.01.02.01
zte/zxa10_b766v2_firmware < 2.01.02.01
zte/zxa10_b76hv3_firmware < 2.01.02.01
zte/zxa10_b800v2_firmware < 2.01.02.01
zte/zxa10_b836ct-a15_firmware < 2.01.02.01
zte/zxa10_b860av2.1_firmware < 2.01.02.01
zte/zxa10_b860h_firmware < 2.01.02.01
zte/zxa10_b866v2-h_firmware < 2.01.02.01
... and 5 more
Published Sep 23, 2022
Tracked Since Feb 18, 2026