There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 29 Sep 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zte
Zte mf296r Zte mf296r Firmware |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:h:zte:mf296r:-:*:*:*:*:*:*:* cpe:2.3:o:zte:mf296r_firmware:mf296r_nordic1_b06:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zte
Zte mf296r Zte mf296r Firmware |
Wed, 18 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Sep 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack. | |
| Title | Buffer Overflow Vulnerability in ZTE MF296R | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: zte
Published: 2024-09-18T01:57:54.052Z
Updated: 2024-09-18T15:27:59.586Z
Reserved: 2022-08-31T15:51:04.696Z
Link: CVE-2022-39068
Updated: 2024-09-18T15:27:54.468Z
Status : Analyzed
Published: 2024-09-18T02:15:09.690
Modified: 2024-09-29T00:41:50.500
Link: CVE-2022-39068
No data.