CVE-2018-7358
55Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.5epss 90%
from disclosure to weapon27 days
Published on NVDNov 14
1st PoC+27d
exploitation probability
90%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short
The ZTE ZXHN H168N router has a flaw that lets unauthorized users perform actions they shouldn't be able to do. This happens because the device doesn't properly control who can make changes to its settings.
Technical detail
The vulnerability exists in versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7, and V2.2.0_PK11T due to improper change control mechanisms. An unauthenticated or low-privileged attacker can exploit this to execute unauthorized operations on the affected device, potentially modifying configuration or system behavior.
Summary generated and translated by AI from the official description.
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
ZTE · ZXHN H168Npublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45972cve_referencewww.exploit-db.com/exploits/45972/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.