CVE-2020-6872

moderate-risk
Published 2020-07-20

The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>.

Do I need to act?

-
0.42% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10 Medium
NETWORK / LOW complexity

Affected Products (20)

R8500G4 Firmware
R8500G4 Firmware
R8500G4 Firmware
R8500G4 Firmware
R8500G4 Firmware
R5500G4 Firmware
R5500G4 Firmware
R5500G4 Firmware
R5500G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware
R5300G4 Firmware

Affected Vendors

Zte
45
/ 100
moderate-risk
Severity 23/34 · High
Exploitability 2/34 · Minimal
Exposure 20/34 · Moderate