CVE Database
/

CVE-2020-6872

Back to search

CVE-2020-6872

Published: Jul 20, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>.

VendorProductVersions

n/a

<R5300G4?R8500G4?R5500G4>

affected
<R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020
affected
R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020
affected
R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now