CVE-2017-10931
Estado: ModificadaAlta (7.5)—
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.29%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-10931",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@zte.com.cn",
"affectedData": [
{
"vendor": "ZTE",
"product": "ZX10 1800-2S",
"versions": [
{
"status": "affected",
"version": "All versions prior to V3.00.40"
}
]
}
]
}
],
"published": "2017-09-19T14:29:00.273",
"references": [
{
"url": "http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262",
"tags": [
"Permissions Required"
],
"source": "psirt@zte.com.cn"
},
{
"url": "http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration."
},
{
"lang": "es",
"value": "ZXR10 1800-2S en versiones anteriores a la 3.00.40 restringe incorrectamente las descarga del rango del directorio de archivos para los usuarios WEB. Esto provoca que se pueda descargar cualquier archivo y provocar filtraciones de información como la configuración del sistema."
}
],
"lastModified": "2026-06-17T01:00:56.797",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zte:zxr10_1800-2s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "720817E2-2A6C-458D-A755-734D3950ACB3",
"versionEndExcluding": "3.00.40"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zte:zxr10_1800-2s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CA2AC22D-CC1C-4F6E-AFA1-EEC6C2A294DC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zte:zxr10_2800-4_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1953F140-3D24-4496-B5EB-9E79A2B00DA9",
"versionEndExcluding": "3.00.40"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zte:zxr10_2800-4:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C5A4FC3A-3137-4B81-85D4-48AC72CF1019"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zte:zxr10_3800-8_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C47EA3A-F5B6-4536-A35E-86426A6324C4",
"versionEndExcluding": "3.00.40"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zte:zxr10_3800-8:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6346FA61-050D-4E0A-906C-D2E62D9AA3A1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zte:zxr10_160_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57325750-FFA0-4F1B-A2BA-CC1573509445",
"versionEndExcluding": "3.00.40"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zte:zxr10_160:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6389B69E-A7E2-4BF3-A628-4F5C0ED6EF86"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@zte.com.cn"
}