There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1028624 | Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2023-01-06 19:15
Updated : 2023-08-08 14:21
NVD link : CVE-2022-39072
Mitre link : CVE-2022-39072
CVE.ORG link : CVE-2022-39072
JSON object : View
Products Affected
                zte
- mf286r_firmware
- mf289d_firmware
- mf286r
- mf289d
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
