Back to search
CVE-2020-6880
Published: Dec 1, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.
| Vendor | Product | Versions |
|---|---|---|
n/a | ZXV10 W908 | affected all versions before MIPS_A_1022IPV6R3T6P7Y20 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now