CVE-2020-6872 describes a stored Cross-Site Scripting (XSS) vulnerability in the server management software module of various ZTE R5300G4, R8500G4, and R5500G4 server models. An attacker can inject malicious code via the foreground login page, leading to the execution of predefined scripts in a user's browser. This vulnerability is rated Medium severity with a CVSS score of 6.1. It has a network attack vector and low attack complexity, requiring user interaction to trigger, and can result in limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
03.05.0020CPE matchmatch criteria | cpe:2.3:o:zte:r8500g4_firmware:03.05.0020:*:*:*:*:*:*:* | ||
03.05.0400CPE matchmatch criteria | cpe:2.3:o:zte:r8500g4_firmware:03.05.0400:*:*:*:*:*:*:* | ||
03.06.0100CPE matchmatch criteria | cpe:2.3:o:zte:r8500g4_firmware:03.06.0100:*:*:*:*:*:*:* | ||
03.07.0101CPE matchmatch criteria | cpe:2.3:o:zte:r8500g4_firmware:03.07.0101:*:*:*:*:*:*:* | ||
03.07.0103CPE matchmatch criteria | cpe:2.3:o:zte:r8500g4_firmware:03.07.0103:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.