peter bassill · operator
$ cve CVE-2015-8703 JSON

CVE-2015-8703 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 4.9% (pctl 92)

Patch early

A public exploit exists.

Description

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS4.86% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2015-12-30
Last modified2026-06-17

Affected (4)

VendorProduct
ztezxhn h108n r1a
ztezxhn h108n r1a firmware
ztezxv10 w300
ztezxv10 w300 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD