CVE-2015-8703 describes an access restriction bypass vulnerability in ZTE ZXHN H108N R1A and ZXV10 W300 routers. Remote authenticated users can exploit this flaw to read configuration files, thereby discovering sensitive credentials and keys. The vulnerability has a CVSS v3.0 score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity, requiring only low privileges, and resulting in high confidentiality impact without affecting integrity or availability. While there is no evidence of active exploitation (KEV list), an ExploitDB entry (EDB-38773) exists, suggesting proof-of-concept code is publicly available. Despite this, community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= zte.bhs.zxhnh108nr1a.h_peCPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h108n_r1a_firmware:*:*:*:*:*:*:*:* | ||
<= w300v1.0.0f_er1_peCPE matchmatch criteria | cpe:2.3:o:zte:zxv10_w300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.