CVE-2023-25642

MEDIUM

ZTE Mc801a Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. 

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0022
EPSS Percentile 44.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-120
Status published
Products (2)
zte/mc801a1_firmware mc801a1_elisa1_b04
zte/mc801a_firmware mc801a_elisa3_b19
Published Dec 14, 2023
Tracked Since Feb 18, 2026