CVE-2022-39075 describes an unauthorized access vulnerability in certain ZTE mobile phones, where a malicious application can delete system files without user permission. With a CVSS score of 7.1 (HIGH), this vulnerability requires user interaction (UI:R) to install a malicious application, but once installed, it can lead to high integrity and availability impacts (I:H/A:H). There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion, indicating a low exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< m02CPE matchmatch criteria | cpe:2.3:o:zte:blade_a52_firmware:*:*:*:*:*:*:*:* | ||
< m07CPE matchmatch criteria | cpe:2.3:o:zte:blade_a51_firmware:*:*:*:*:*:*:*:* | ||
< m09CPE matchmatch criteria | cpe:2.3:o:zte:blade_a3_lite_firmware:*:*:*:*:*:*:*:* | ||
< m05CPE matchmatch criteria | cpe:2.3:o:zte:blade_a5_2020_firmware:*:*:*:*:*:*:*:* | ||
< 1.14CPE matchmatch criteria | cpe:2.3:o:zte:blade_l210_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.