---
cve: "CVE-2019-3411"
severity: "HIGH"
cvss: 8.1
epss: "1.3%"
vendor: "ZTE"
kev: false
exploited: false
published: "2019-06-11 20:29:01"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T20:27:35+02:00"
---

# CVE-2019-3411

> 8.1 HIGH

## Beschreibung

All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010686>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-3411) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
