ZTE ZXEDM iEMS
cpe:2.3:h:zte:zxmp_m721:*:*:*:*:*:*:*, +1 more
A password reset vulnerability has been identified in the ZTE ZXEDM iEMS product, affecting all users. The issue arises because the cloud EMS portal management does not properly restrict access to the user list acquisition function. This oversight allows attackers to retrieve information about all users through the user list interface. Once they have this information, attackers can reset the passwords of the users, potentially leading to unauthorized operations.
Exploitation of this vulnerability could result in unauthorized password resets, allowing attackers to perform unauthorized actions on behalf of the affected users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.