There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges.
References
Link | Resource |
---|---|
https://https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1034404 | Broken Link Vendor Advisory |
https://https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1034404 | Broken Link Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
28 Jan 2025, 15:36
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:zte:zxcloud_irai_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:a:zte:zxcloud_irai:-:*:*:*:*:*:*:* cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:* |
09 Jan 2024, 20:00
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
First Time |
Zte zxcloud Irai Firmware
Zte zxcloud Irai Zte |
|
CPE | cpe:2.3:o:zte:zxcloud_irai_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zte:zxcloud_irai:-:*:*:*:*:*:*:* |
|
CWE | CWE-427 | |
References | () https://https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1034404 - Broken Link, Vendor Advisory |
03 Jan 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-03 02:15
Updated : 2025-01-28 15:36
NVD link : CVE-2023-41780
Mitre link : CVE-2023-41780
JSON object : View
Products Affected
zte
- zxcloud_irai
CWE
CWE-427
Uncontrolled Search Path Element