CVE-2012-4746: ZTE Zxdsl

Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

Affected products

  • ZTE Zxdsl: version 831iiv7.5.0a_z29_ov only

Published 2012-08-31. Last modified 2026-06-16.