All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.
                
            References
                    | Link | Resource | 
|---|---|
| http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1009383 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2018-11-16 15:29
Updated : 2019-10-09 23:42
NVD link : CVE-2018-7363
Mitre link : CVE-2018-7363
CVE.ORG link : CVE-2018-7363
JSON object : View
Products Affected
                zte
- zxhn_f670_firmware
- zxhn_f670
CWE
                
                    
                        
                        CWE-863
                        
            Incorrect Authorization
