CVE-2017-10935
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in ZTE ZXR10 1800-2S routers lets authenticated users change other users' passwords without proper verification, bypassing security controls that should protect account access.
Technical detail
The vulnerability allows authenticated users to bypass password authentication mechanisms and modify other users' credentials. The attack requires prior authentication but exploits insufficient validation of password change operations, compromising account integrity across the system.
Summary generated and translated by AI from the official description.
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
Affected products
ZTE · ZXR10 1800-2S