CVE-2022-39069

MEDIUM

ZTE ZAIP-AIE < 8.22.02 - SQL Injection

Title source: llm
STIX 2.1

Description

There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0043
EPSS Percentile 62.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
zte/zaip-aie < 8.22.02
Published Nov 08, 2022
Tracked Since Feb 18, 2026