CVE-2024-45415
Estado: AplazadaCrítica (9.8)—
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.48%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-121
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-45415",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-45415",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-18T15:23:11.553907Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:zte:zxhn_z500_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_z500_firmware",
"versions": [
{
"status": "affected",
"version": "V1.0.1.1B2.1000"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_e500_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_e500_firmware",
"versions": [
{
"status": "affected",
"version": "V1.0.1.1B2.1000"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_h108n_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_h108n_firmware",
"versions": [
{
"status": "affected",
"version": "V2.6.20.ROST12"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_e2615_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_e2615_firmware",
"versions": [
{
"status": "affected",
"version": "V1.0.1"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_e2603_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_e2603_firmware",
"versions": [
{
"status": "affected",
"version": "V1.0.1"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_e2618_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_e2618_firmware",
"versions": [
{
"status": "affected",
"version": "V1.0.0.2B4.3000"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_e1600_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_e1600_firmware",
"versions": [
{
"status": "affected",
"version": "V1.0.0.2B1.1000"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_h338a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_h338a_firmware",
"versions": [
{
"status": "affected",
"version": "V1.5.0_H3A.1T9P1-o"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_h168n_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_h168n_firmware",
"versions": [
{
"status": "affected",
"version": "V3.5.5_CO.1T1"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:zte:zxhn_h168a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "zte",
"product": "zxhn_h168a_firmware",
"versions": [
{
"status": "affected",
"version": "TTN.1T1_211029"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-09-16T21:15:45.943",
"references": [
{
"url": "https://wr3nchsr.github.io/zte-multiple-routers-httpd-vulnerabilities-advisory/",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-121"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability."
},
{
"lang": "es",
"value": "El binario HTTPD en varios ZTE routers tiene una vulnerabilidad de desbordamiento de búfer basada en pila en la función check_data_integrity. Esta función es responsable de validar la suma de comprobación de los datos en la solicitud posterior. La suma de comprobación se envía cifrada en la solicitud, la función la descifra y almacena la suma de comprobación en la pila sin validarla. Un atacante no autenticado puede obtener RCE como superusuario explotando esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T07:54:10.440",
"sourceIdentifier": "cve@mitre.org"
}