CVE-2015-7248 is a high-severity information disclosure vulnerability affecting ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE firmware. Remote attackers can exploit this flaw to discover usernames and password hashes by directly reading the HTML source code of cgi-bin/webproc. With a CVSS score of 7.5, this vulnerability allows unauthenticated attackers to gain sensitive information over the network without user interaction, leading to a high impact on confidentiality. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= zte.bhs.zxhnh108nr1a.h_peCPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h108n_r1a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.