V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Link | Tags |
---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1012162 | vendor advisory |
http://packetstormsecurity.com/files/159135/ZTE-F602W-CAPTCHA-Bypass.html | exploit vdb entry third party advisory |