Loading
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
Use CWE-89, Zte vendor hub and Mf286r Firmware product page to widen CVE-2022-39072 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-39073, CVE-2022-39066 and CVE-2023-25649 for nearby disclosures in the same product family.