CVE detail
CVE-2019-3425 — CVE-2019-3425
Published 2019-11-08 · Modified 2026-06-17 · Vendor zte · Product zxupn-9000e_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0097
EPSS probability
exploitation probability, 30d
59.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References