Loading
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
Use CWE-77, Zte vendor hub and Mc801a Firmware product page to widen CVE-2023-25643 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-25644 and CVE-2023-25642 for nearby disclosures in the same product family.