{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T11:55:04.982","vulnerabilities":[{"cve":{"id":"CVE-2019-3411","sourceIdentifier":"psirt@zte.com.cn","published":"2019-06-11T20:29:01.717","lastModified":"2026-06-17T02:35:07.003","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components."},{"lang":"es","value":"Todas las versiones hasta BD_R218V2.4 del producto ZTE MF920 se ven afectadas por la vulnerabilidad de la fuga de información. Debido a que algunas interfaces pueden obtener la contraseña de inicio de sesión de WebUI sin iniciar sesión, un atacante puede aprovechar la vulnerabilidad para obtener información confidencial sobre los componentes afectados."}],"affected":[{"source":"psirt@zte.com.cn","affectedData":[{"vendor":"ZTE","product":"ZTE MF920","versions":[{"version":"unspecified","lessThanOrEqual":"All versions up to BD_R218V2.4","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV30":[{"source":"psirt@zte.com.cn","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zte:mf920_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"bd_r218v2.4","matchCriteriaId":"3052E3A1-DF21-4113-8EA0-4D64B9DBEA31"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zte:mf920:-:*:*:*:*:*:*:*","matchCriteriaId":"D5DA3A18-9965-4003-9F69-B0FF6B2F59E7"}]}]}],"references":[{"url":"http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010686","source":"psirt@zte.com.cn","tags":["Vendor Advisory"]},{"url":"http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010686","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}