Description
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
References (1)
Core 1
Core References
Scores
CVSS v3
5.9
EPSS
0.0022
EPSS Percentile
44.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Details
CWE
CWE-120
Status
published
Products (2)
zte/mc801a1_firmware
mc801a1_elisa1_b04
zte/mc801a_firmware
mc801a_elisa3_b19
Published
Dec 14, 2023
Tracked Since
Feb 18, 2026