« Volver al listado

CVE-2024-45415

Estado: AplazadaCrítica (9.8)—

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45415",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45415",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-18T15:23:11.553907Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_z500_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_z500_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.0.1.1B2.1000"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_e500_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_e500_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.0.1.1B2.1000"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_h108n_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_h108n_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V2.6.20.ROST12"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_e2615_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_e2615_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.0.1"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_e2603_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_e2603_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.0.1"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_e2618_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_e2618_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.0.0.2B4.3000"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_e1600_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_e1600_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.0.0.2B1.1000"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_h338a_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_h338a_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V1.5.0_H3A.1T9P1-o"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_h168n_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_h168n_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "V3.5.5_CO.1T1"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zte:zxhn_h168a_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zte",
          "product": "zxhn_h168a_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "TTN.1T1_211029"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-09-16T21:15:45.943",
  "references": [
    {
      "url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory/",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability."
    },
    {
      "lang": "es",
      "value": "El binario HTTPD en varios ZTE routers tiene una vulnerabilidad de desbordamiento de búfer basada en pila en la función check_data_integrity. Esta función es responsable de validar la suma de comprobación de los datos en la solicitud posterior. La suma de comprobación se envía cifrada en la solicitud, la función la descifra y almacena la suma de comprobación en la pila sin validarla. Un atacante no autenticado puede obtener RCE como superusuario explotando esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T07:54:10.440",
  "sourceIdentifier": "cve@mitre.org"
}