---
cve: "CVE-2018-7360"
severity: "CRITICAL"
cvss: 9.6
epss: "100%"
vendor: "ZTE"
kev: false
exploited: false
published: "2018-11-16 15:29:00"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T07:21:12+02:00"
---

# CVE-2018-7360

> 9.6 CRITICAL

## Beschreibung

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may allow an unauthenticated attacker to get the GPON SN information via appviahttp service.

## CVSS-Vektor

```
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1009383>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-7360) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
