---
cve: "CVE-2024-22067"
severity: "MEDIUM"
cvss: 6.8
epss: "0.7%"
vendor: "ZTE"
kev: false
exploited: false
published: "2024-11-18 07:15:17"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T22:17:22+02:00"
---

# CVE-2024-22067

> 6.8 MEDIUM

## Beschreibung

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/6179526095692935173>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-22067) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
