CVE-2022-39072: ZTE MF286R Firmware
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
Affected products
- ZTE MF286R Firmware: version nordic_mf286r_b06 only
- ZTE MF289D Firmware: version cr_tmoczmf289dv1.0.0b07 only
Published 2023-01-06. Last modified 2026-06-17.