Loading
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.
Use CWE-89, Zte vendor hub and Mf286r Firmware product page to widen CVE-2022-39066 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-39073, CVE-2023-25649 and CVE-2022-39067 for nearby disclosures in the same product family.